CVE-2017-13082
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 4.58% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-323, CWE-330
- Affected
- canonical/ubuntu linux · debian/debian linux · freebsd/freebsd · opensuse/leap · redhat/enterprise linux desktop · redhat/enterprise linux server · w1.fi/hostapd · w1.fi/wpa supplicant · suse/linux enterprise desktop · suse/linux enterprise point of sale · suse/linux enterprise server · suse/openstack cloud
- Source
- cret@cert.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.html
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007.txtThird Party Advisory
- http://www.debian.org/security/2017/dsa-3999Third Party Advisory
- http://www.kb.cert.org/vuls/id/228519Third Party Advisory, US Government Resource
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.securityfocus.com/bid/101274Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039570Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039571Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039573Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039581Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-3455-1Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2907Third Party Advisory
- https://access.redhat.com/security/vulnerabilities/kracksThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-901333.pdf
- https://cert.vde.com/en-us/advisories/vde-2017-005
- https://github.com/vanhoefm/krackattacks-test-ap-ftExploit, Third Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-17-299-02
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1066697
- https://security.FreeBSD.org/advisories/FreeBSD-SA-17:07.wpa.ascThird Party Advisory
- https://security.gentoo.org/glsa/201711-03
- https://source.android.com/security/bulletin/2017-11-01
- https://support.lenovo.com/us/en/product_security/LEN-17420Third Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171016-wpaThird Party Advisory
- https://w1.fi/security/2017-1/wpa-packet-number-reuse-with-replayed-messages.txtThird Party Advisory
- https://www.krackattacks.com/Technical Description, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.html
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007.txtThird Party Advisory
- http://www.debian.org/security/2017/dsa-3999Third Party Advisory
- http://www.kb.cert.org/vuls/id/228519Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.