CVE-2017-13078

CWE-323CWE-330CWE-32021 documents12 sources
Severity
5.3MEDIUM
EPSS
0.9%
top 23.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateMay 13

Description

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.

CVSS vector

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages13 packages

Debianwpa< 2:2.4-1.1+3
Ubuntuwpa< 2.1-0ubuntu1.5+1
Debianfirmware-nonfree< 20180825-1+3
NVDopensuse/leap42.2, 42.3+1

Also affects: Freebsd 10, 10.4, 11, 11.1, Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.04

🔴Vulnerability Details

4
GHSA
GHSA-5fh3-v3jw-rc9h: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within2022-05-13
OSV
CVE-2017-13078: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within2017-10-17
CVEList
CVE-2017-13078: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within2017-10-17
OSV
wpa vulnerabilities2017-10-16

📋Vendor Advisories

13
Apple
CVE-2017-13078: Wi-Fi Update for Boot Camp 6.4.02018-07-05
Apple
CVE-2017-13078: AirPort Base Station Firmware Update 7.7.92017-12-12
Apple
CVE-2017-13078: AirPort Base Station Firmware Update 7.6.92017-12-12
Android
CVE-2017-13078: Android Security Bulletin 2017-11-01 CVE: CVE-2017-13078 Severity: HIGH Type: EoP Affected AOSP versions: 52017-11-01
Apple
CVE-2017-13078: iOS 11.12017-10-31

💬Community

3
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 wpa_supplicant: various flaws [fedora-all]2017-10-16
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 hostapd: various flaws [fedora-all]2017-10-16
Bugzilla
CVE-2017-13078 wpa_supplicant: Reinstallation of the group key in the 4-way handshake2017-09-14
CVE-2017-13078 (MEDIUM CVSS 5.3) | Wi-Fi Protected Access (WPA and WPA | cvebase.io