SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-13080

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.

MEDIUM 5.3EPSS 2.28%

Does this matter?

Lower severity and a low EPSS score (2.28%). Track it; it rarely justifies an emergency change on its own.

Description

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
2.28% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-323, CWE-330
Affected
canonical/ubuntu linux · debian/debian linux · freebsd/freebsd · opensuse/leap · redhat/enterprise linux desktop · redhat/enterprise linux server · w1.fi/hostapd · w1.fi/wpa supplicant · suse/linux enterprise desktop · suse/linux enterprise point of sale · suse/linux enterprise server · suse/openstack cloud
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.