CVE-2017-13080
published 2017-10-17CVE-2017-13080: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio…
PriorityP428medium5.3CVSS 3.0
AVAACHPRNUINSUCNIHAN
EPSS
2.28%
81.2th percentile
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
Affected
121 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | airport_base_station_firmware_update | — | — |
| apple | airport_base_station_firmware_update | — | — |
| apple | ios | — | — |
| apple | ios | — | — |
| apple | macos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20 | — | — |
| apple | macos_high_sierra_10.13.4_security_update_2018-002_sierra_and_security_update_20 | — | — |
| apple | tvos | — | — |
| apple | tvos | — | — |
| apple | watchos | — | — |
| apple | watchos | — | — |
| apple | wi-fi_update_for_boot_camp | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firmware-nonfree | < firmware-nonfree 20180825-1 (bookworm) | firmware-nonfree 20180825-1 (bookworm) |
| debian | linux | < firmware-nonfree 20180825-1 (bookworm) | firmware-nonfree 20180825-1 (bookworm) |
| debian | wpa | < firmware-nonfree 20180825-1 (bookworm) | firmware-nonfree 20180825-1 (bookworm) |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.13.13-1 | 4.13.13-1 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_cisco6.8MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_msrc4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2017-13080: Wi-Fi Update for Boot Camp 6.4.0
vendor_apple·2018-07-05·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: Wi-Fi Update for Boot Camp 6.4.0
Apple Security Update: About the security content of Wi-Fi Update for Boot Camp 6.4.0
Product: Wi-Fi Update for Boot Camp
Version: 6.4.0
CVE: CVE-2017-13080
Component: Wi-Fi
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA multicast/GTK clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
CISA ICS
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update E)
cisa_ics·2018-04-24
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update E)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update E)
Last RevisedJune 19, 2019
Alert CodeICSA-17-318-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.8
- ATTENTION: Exploitable remotely/low skill level to exploit/public exploits are available.
- Vendor: Siemens
- Equipment: SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products
- Vulnerabilities: Security Features
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the updated advisory titled ICSA-17-318-01 Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update D) that was published April 24,
CISA ICS
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update F)
cisa_ics·2018-04-24
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update F)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update F)
Last RevisedApril 09, 2019
Alert CodeICSA-17-318-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.8
- ATTENTION: Exploitable remotely/low skill level to exploit/public exploits are available.
- Vendor: Siemens
- Equipment: SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products
- Vulnerabilities: Security Features
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the updated advisory titled ICSA-17-318-01 Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update D) that was published April 24
Apple
CVE-2017-13080: macOS High Sierra 10.13.4, Security Update 2018-002 Sierra, and Security Update 2018-002 El Capitan
vendor_apple·2018-03-29·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: macOS High Sierra 10.13.4, Security Update 2018-002 Sierra, and Security Update 2018-002 El Capitan
Apple Security Update: About the security content of macOS High Sierra 10.13.4, Security Update 2018-002 Sierra, and Security Update 2018-002 El Capitan
Product: macOS High Sierra 10.13.4, Security Update 2018-002 Sierra, and Security Update 2018-002 El Capitan
CVE: CVE-2017-13080
Component: EFI
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
CISA ICS
PEPPERL+FUCHS/ecom instruments WLAN Capable Devices using the WPA2 Protocol
cisa_ics·2017-12-19
PEPPERL+FUCHS/ecom instruments WLAN Capable Devices using the WPA2 Protocol
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
PEPPERL+FUCHS/ecom instruments WLAN Capable Devices using the WPA2 Protocol
Last RevisedDecember 19, 2017
Alert CodeICSA-17-353-02
## CVSS v3 8.1
ATTENTION: Low skill level is needed to exploit. Public exploits are available.
Vendor: PEPPERL+FUCHS/ecom instruments
Equipment: WLAN capable devices using the WPA2 Protocol
Vulnerabilities: Reusing a Nonce
## AFFECTED PRODUCTS
PEPPERL+FUCHS/ecom instruments reports that these vulnerabilities affect all versions of the following WLAN capable devices using the WPA2 Protocol:
- Tab-Ex 01,
- Ex-Handy 09,
- Ex-Handy 209,
- Smart-
Apple
CVE-2017-13080: AirPort Base Station Firmware Update 7.7.9
vendor_apple·2017-12-12·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: AirPort Base Station Firmware Update 7.7.9
Apple Security Update: About the security content of AirPort Base Station Firmware Update 7.7.9
Product: AirPort Base Station Firmware Update
Version: 7.7.9
CVE: CVE-2017-13080
Component: AirPort Base Station Firmware
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA multicast/GTK clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
Apple
CVE-2017-13080: AirPort Base Station Firmware Update 7.6.9
vendor_apple·2017-12-12·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: AirPort Base Station Firmware Update 7.6.9
Apple Security Update: About the security content of AirPort Base Station Firmware Update 7.6.9
Product: AirPort Base Station Firmware Update
Version: 7.6.9
CVE: CVE-2017-13080
Component: AirPort Base Station Firmware
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA multicast/GTK clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
Ubuntu
Linux firmware vulnerabilities
vendor_ubuntu·2017-12-06·CVSS 5.3
CVE-2017-13080 [MEDIUM] Linux firmware vulnerabilities
Title: Linux firmware vulnerabilities
Summary: Several security issues were fixed in linux-firmware.
Mathy Vanhoef discovered that the firmware for several Intel WLAN
devices incorrectly handled WPA2 in relation to Wake on WLAN. A
remote attacker could use this issue with key reinstallation attacks
to obtain sensitive information. (CVE-2017-13080, CVE-2017-13081)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Apple
CVE-2017-13080: watchOS 4.2
vendor_apple·2017-12-05·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: watchOS 4.2
Apple Security Update: About the security content of watchOS 4.2
Product: watchOS
Version: 4.2
CVE: CVE-2017-13080
Component: Wi-Fi
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA multicast/GTK clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
Apple
CVE-2017-13080: tvOS 11.2
vendor_apple·2017-12-04·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: tvOS 11.2
Apple Security Update: About the security content of tvOS 11.2
Product: tvOS
Version: 11.2
CVE: CVE-2017-13080
Component: Released for Apple TV 4K in tvOS 11.1.
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA multicast/GTK clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
Apple
CVE-2017-13080: iOS 11.2
vendor_apple·2017-12-02·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: iOS 11.2
Apple Security Update: About the security content of iOS 11.2
Product: iOS
Version: 11.2
CVE: CVE-2017-13080
Component: Wi-Fi
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA multicast/GTK clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
CISA ICS
PHOENIX CONTACT WLAN Capable Devices using the WPA2 Protocol
cisa_ics·2017-11-21·CVSS 5.3
[MEDIUM] PHOENIX CONTACT WLAN Capable Devices using the WPA2 Protocol
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
PHOENIX CONTACT WLAN Capable Devices using the WPA2 Protocol
Last RevisedNovember 21, 2017
Alert CodeICSA-17-325-01
## CVSS v3 6.8
ATTENTION: Public exploits are available.
Vendor: PHOENIX CONTACT
Equipment: WLAN capable devices using the WPA2 Protocol
Vulnerabilities: Reusing a Nonce
## AFFECTED PRODUCTS
PHOENIX CONTACT reports that these vulnerabilities affect all versions of the following WLAN capable devices using the WPA2 Protocol:
- BL2 BPC,
- BL2 PPC,
- FL COMSERVER WLAN 232/422/485,
- FL WLAN 110x,
- FL WLAN 210x,
- FL WLAN 510x,
- FL WLAN 230 AP 802-11,
- F
CISA ICS
ABB TropOS (Update A)
cisa_ics·2017-11-14
ABB TropOS (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB TropOS (Update A)
Last RevisedFebruary 15, 2018
Alert CodeICSA-17-318-02A
## CVSS v3 6.8
Vendor: ABB
Equipment: TropOS
Vulnerabilities: Security Features
## UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-17-318-02 ABB TropOS that was published November 14, 2017, on the NCCIC/ICS-CERT website.
## AFFECTED PRODUCTS
ABB reports that the key reinstallation attacks (KRACK) potentially affect all TropOS broadband mesh routers and bridges operating on Mesh OS release 8.5.2 or prior.
## IMPACT
Successful exploitation of these vul
Android
CVE-2017-13080: Android Security Bulletin 2017-11-01
CVE: CVE-2017-13080
Severity: HIGH
Type: EoP
Affected AOSP versions: 5
vendor_android·2017-11-01·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: Android Security Bulletin 2017-11-01
CVE: CVE-2017-13080
Severity: HIGH
Type: EoP
Affected AOSP versions: 5
Android Security Bulletin 2017-11-01
CVE: CVE-2017-13080
Severity: HIGH
Type: EoP
Affected AOSP versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0
References: A-67737262
Apple
CVE-2017-13080: watchOS 4.1
vendor_apple·2017-10-31·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: watchOS 4.1
Apple Security Update: About the security content of watchOS 4.1
Product: watchOS
Version: 4.1
CVE: CVE-2017-13080
Component: Wi-Fi
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA multicast/GTK clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
Apple
CVE-2017-13080: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
vendor_apple·2017-10-31·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
Apple Security Update: About the security content of macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
Product: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan
CVE: CVE-2017-13080
Component: Wi-Fi
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA multicast/GTK clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
Apple
CVE-2017-13080: tvOS 11.1
vendor_apple·2017-10-31·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: tvOS 11.1
Apple Security Update: About the security content of tvOS 11.1
Product: tvOS
Version: 11.1
CVE: CVE-2017-13080
Component: Wi-Fi
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA multicast/GTK clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
Apple
CVE-2017-13080: iOS 11.1
vendor_apple·2017-10-31·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: iOS 11.1
Apple Security Update: About the security content of iOS 11.1
Product: iOS
Version: 11.1
CVE: CVE-2017-13080
Component: Wi-Fi
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA multicast/GTK clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
BSD
FreeBSD-SA-17:07.wpa: WPA2 protocol vulnerability
bsd_advisories·2017-10-17·CVSS 6.8
CVE-2017-13077 [MEDIUM] FreeBSD-SA-17:07.wpa: WPA2 protocol vulnerability
FreeBSD-SA-17:07.wpa Security Advisory
The FreeBSD Project
Topic: WPA2 protocol vulnerability
Category: contrib
Module: wpa
Announced: 2017-10-16
Credits: Mathy Vanhoef
Affects: All supported versions of FreeBSD.
Corrected: 2017-10-17 17:30:18 UTC (stable/11, 11.1-STABLE)
2017-10-17 17:57:18 UTC (releng/11.1, 11.1-RELEASE-p2)
2017-10-17 17:56:03 UTC (releng/11.0, 11.0-RELEASE-p13)
2017-10-19 03:18:22 UTC (stable/10, 10.4-STABLE)
2017-10-19 03:20:17 UTC (releng/10.4, 10.4-RELEASE-p1)
2017-10-19 03:19:42 UTC (releng/10.3, 10.3-RELEASE-p22)
CVE Name: CVE-2017-13077, CVE-2017-13078, CVE-2017-13079,
CVE-2017-13080, CVE-2017-13081, CVE-2017-13082,
CVE-2017-13086, CVE-2017-13087, CVE-2017-13088
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields
Red Hat
wpa_supplicant: Reinstallation of the group key in the group key handshake
vendor_redhat·2017-10-16·CVSS 5.3
CVE-2017-13080 [MEDIUM] CWE-323 wpa_supplicant: Reinstallation of the group key in the group key handshake
wpa_supplicant: Reinstallation of the group key in the group key handshake
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
A new exploitation technique called key reinstallation attacks (KRACK) affecting WPA2 has been discovered. A remote attacker within Wi-Fi range could exploit this attack to decrypt Wi-Fi traffic or possibly inject forged Wi-Fi packets by reinstalling a previously used group key (GTK) during a group key handshake.
Statement: This issue affects the versions of wpa_supplicant as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: wpa_supplicant (Red Hat Enterprise Linux 5) - Will not fix
Cisco
Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
vendor_cisco·2017-10-16·CVSS 6.8
CVE-2017-13077 [MEDIUM] CWE-320 Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
On October 16, 2017, a research paper with the title “Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2” was made publicly available. This paper discusses seven vulnerabilities affecting session key negotiation in both the Wi-Fi Protected Access (WPA) and the Wi-Fi Protected Access II (WPA2) protocols. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point. Additional research also led to the discovery of three additional vulnerabilities (not discussed in the original paper) affecting wireless supplicant supporting either the 802.11z (Extensions to Direct-Link Setup) standard or the 802.11v (
Ubuntu
wpa_supplicant and hostapd vulnerabilities
vendor_ubuntu·2017-10-16·CVSS 7.5
CVE-2016-4476 [HIGH] wpa_supplicant and hostapd vulnerabilities
Title: wpa_supplicant and hostapd vulnerabilities
Summary: Several security issues were fixed in wpa_supplicant.
Mathy Vanhoef discovered that wpa_supplicant and hostapd incorrectly
handled WPA2. A remote attacker could use this issue with key
reinstallation attacks to obtain sensitive information. (CVE-2017-13077,
CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081,
CVE-2017-13082, CVE-2017-13086, CVE-2017-13087, CVE-2017-13088)
Imre Rad discovered that wpa_supplicant and hostapd incorrectly handled
invalid characters in passphrase parameters. A remote attacker could use
this issue to cause a denial of service. (CVE-2016-4476)
Imre Rad discovered that wpa_supplicant and hostapd incorrectly handled
invalid characters in passphrase parameters. A local attacker could use
this
Microsoft
Windows Wireless WPA Group Key Reinstallation Vulnerability
vendor_msrc·2017-10-10·CVSS 4.2
CVE-2017-13080 [MEDIUM] Windows Wireless WPA Group Key Reinstallation Vulnerability
Windows Wireless WPA Group Key Reinstallation Vulnerability
Description: A spoofing vulnerability exists in the Windows implementation of wireless networking. An attacker who successfully exploited this vulnerability could potentially replay broadcast and/or multicast traffic to hosts on a WPA or WPA 2-protected wireless network.
Multiple conditions would need to be met in order for an attacker to exploit the vulnerability – the attacker would need to be within the physical proximity of the targeted user, and the user's computer would need to have wireless networking enabled. The attacker would then need to execute a man-in-the-middle (MitM) attack to intercept traffic between the target computer and wireless access point.
The security update addresses the vulnerability by changing how Wi
Debian
CVE-2017-13080: firmware-nonfree - Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Tempora...
vendor_debian·2017·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: firmware-nonfree - Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Tempora...
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
Scope: local
bookworm: resolved (fixed in 20180825-1)
bullseye: resolved (fixed in 20180825-1)
forky: resolved (fixed in 20180825-1)
sid: resolved (fixed in 20180825-1)
trixie: resolved (fixed in 20180825-1)
Cisco
Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
vendor_cisco·CVSS 3.0
CVE-2017-13080 Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
CVE-2017-13080: Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
On October 16, 2017, a research paper with the title “Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2” was made publicly available. This paper discusses seven vulnerabilities affecting session key negotiation in both the Wi-Fi Protected Access (WPA) and the Wi-Fi Protected Access II (WPA2) protocols. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point. Additional research also led to the discovery of three additional vulnerabilities (not discussed in the original paper) affecting wireless supplicant supporting either the 802.11z (Extensions to Direct-Link Setup) standard o
GHSA
GHSA-jq36-53qv-7v3m: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker withi
ghsa_unreviewed·2022-05-13
CVE-2017-13080 [MEDIUM] CWE-323 GHSA-jq36-53qv-7v3m: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker withi
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
OSV
linux-firmware vulnerabilities
osv·2017-12-06·CVSS 5.3
CVE-2017-13080 [MEDIUM] linux-firmware vulnerabilities
linux-firmware vulnerabilities
Mathy Vanhoef discovered that the firmware for several Intel WLAN
devices incorrectly handled WPA2 in relation to Wake on WLAN. A
remote attacker could use this issue with key reinstallation attacks
to obtain sensitive information. (CVE-2017-13080, CVE-2017-13081)
OSV
CVE-2017-13080: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker withi
osv·2017-10-17·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker withi
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
OSV
wpa vulnerabilities
osv·2017-10-16·CVSS 7.5
CVE-2017-13077 [HIGH] wpa vulnerabilities
wpa vulnerabilities
Mathy Vanhoef discovered that wpa_supplicant and hostapd incorrectly
handled WPA2. A remote attacker could use this issue with key
reinstallation attacks to obtain sensitive information. (CVE-2017-13077,
CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081,
CVE-2017-13082, CVE-2017-13086, CVE-2017-13087, CVE-2017-13088)
Imre Rad discovered that wpa_supplicant and hostapd incorrectly handled
invalid characters in passphrase parameters. A remote attacker could use
this issue to cause a denial of service. (CVE-2016-4476)
Imre Rad discovered that wpa_supplicant and hostapd incorrectly handled
invalid characters in passphrase parameters. A local attacker could use
this issue to cause a denial of service, or possibly execute arbitrary
code. (CVE-2016-4477)
Kernel
Merge tag 'mac80211-for-davem-2017-10-16' of git://git.kernel.org/pub/scm/linux/kernel/git/jberg/mac80211
kernel_security·2017-10-16·CVSS 5.3
CVE-2017-13080 [MEDIUM] Merge tag 'mac80211-for-davem-2017-10-16' of git://git.kernel.org/pub/scm/linux/kernel/git/jberg/mac80211
Merge tag 'mac80211-for-davem-2017-10-16' of git://git.kernel.org/pub/scm/linux/kernel/git/jberg/mac80211
Johannes Berg says:
Just a single fix, for a WoWLAN-related part of CVE-2017-13080.
Signed-off-by: David S. Miller
Kernel
mac80211: accept key reinstall without changing anything
kernel_security·2017-09-05·CVSS 5.3
CVE-2017-13080 [MEDIUM] mac80211: accept key reinstall without changing anything
mac80211: accept key reinstall without changing anything
When a key is reinstalled we can reset the replay counters
etc. which can lead to nonce reuse and/or replay detection
being impossible, breaking security properties, as described
in the "KRACK attacks".
In particular, CVE-2017-13080 applies to GTK rekeying that
happened in firmware while the host is in D3, with the second
part of the attack being done after the host wakes up. In
this case, the wpa_supplicant mitigation isn't sufficient
since wpa_supplicant doesn't know the GTK material.
In case this happens, simply silently accept the new key
coming from userspace but don't take any action on it since
it's the same key; this keeps the PN replay counters intact.
Signed-off-by: Johannes Berg
No detection rules found.
No public exploits indexed.
HackerOne
Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse
hackerone·2017-11-03·CVSS 6.8
CVE-2017-13077 [MEDIUM] Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse
Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse
Full background information is at [krackattacks.com](https://www.krackattacks.com) and all detailed information can be found in our [research paper](https://papers.mathyvanhoef.com/ccs2017.pdf).
# Key Reinstallation Attack: 4-way handshake example
We use the 4-way handshake to illustrate the idea behind key reinstallation attacks (CVE-2017-13077).
Note that in practice, all protected Wi-Fi network rely on the 4-way handshake to derive a fresh session key (PTK) from some shared secret.
### Step 1. Channel-based man-in-the-middle and initial handshake messages:
* The adversary clones the access point (AP) on a different channel. Say the real AP is on channel 6, and it will be cloned on channel 1.
* The adversary uses Chann
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 wpa_supplicant: various flaws [fedora-all]
bugzilla·2017-10-16·CVSS 6.8
CVE-2017-13077 [MEDIUM] CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 wpa_supplicant: various flaws [fedora-all]
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 wpa_supplicant: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in th
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 hostapd: various flaws [fedora-all]
bugzilla·2017-10-16·CVSS 6.8
CVE-2017-13077 [MEDIUM] CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 hostapd: various flaws [fedora-all]
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 hostapd: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM c
Bugzilla
CVE-2017-13080 wpa_supplicant: Reinstallation of the group key in the group key handshake
bugzilla·2017-09-14·CVSS 5.3
CVE-2017-13080 [MEDIUM] CVE-2017-13080 wpa_supplicant: Reinstallation of the group key in the group key handshake
CVE-2017-13080 wpa_supplicant: Reinstallation of the group key in the group key handshake
A new exploitation technique called key reinstallation attacks used to break Wi-Fi handshakes that negotiate session keys was discovered. These attacks target the Wi-Fi/WPA2 standard. An adversary can trick a client or Access Point (AP) into reinstalling an already-in use group key in the group key handshake. While reinstalling the already in-use key, the associated packet number (sometimes also called nonce) and receive replay counter is reset. This causes nonce reuse, voiding any security the underlying encryption protocol is supposed to provide. For example, it allows decryption or injection of frames, and enables an attacker to replay frames.
Discussion:
Acknowledgments:
Name: CERT
Upstream: M
Qualys
November Patch Tuesday: 53 Vulnerabilities and a Massive Adobe Update
blogs_qualys·2017-11-14·CVSS 7.5
[HIGH] November Patch Tuesday: 53 Vulnerabilities and a Massive Adobe Update
This November Patch Tuesday is moderate in volume and severity. Microsoft released patches to address 53 unique vulnerabilities, with 25 focused on Remote Code Execution fixes. Windows OS receives 14 patches, while the lion’s share is focused on Browsers, Microsoft Office, and Adobe. According to Microsoft, there do not appear to be any actively attacked vulnerabilities in the wild in this patch release.
Interestingly enough, none of the Windows OS patches are listed as Critical this month, but we do recommend focusing on CVE-2017-11830 and CVE-2017-11847 , as they address a Security Feature Bypass, and a Privilege Elevation respectively.
It should also be noted that CVE-2017-11848 , CVE-2017-11827 , CVE-2017-11883 , CVE-2017-8700 have public exploits, but they do not appear to be used i
Krebs
Adobe, Microsoft Patch Critical Cracks
blogs_krebs·2017-11-14·CVSS 5.3
[MEDIUM] Adobe, Microsoft Patch Critical Cracks
It’s Nov. 14 — the second Tuesday of the month (a.k.a. “Patch Tuesday) — and Adobe and Microsoft have issued gobs of security updates for their software. Microsoft’s 11 patch bundles fix more than four-dozen security holes in various Windows versions and Office products — including at least four serious flaws that were publicly disclosed prior to today. Meanwhile, Adobe’s got security updates available for a slew of titles, including Flash Player , Photoshop , Reader and Shockwave .
Four of the vulnerabilities Microsoft fixed today have public exploits, but they do not appear to be used in any active malware campaigns, according to Gill Langston at security vendor Qualys . Perhaps the two most serious flaws likely to impact Windows end users involve vulnerabilities in Microsoft browsers I
Krebs
Adobe, Microsoft Patch Critical Cracks
blogs_krebs·2017-11-14·CVSS 5.3
[MEDIUM] Adobe, Microsoft Patch Critical Cracks
It’s Nov. 14 — the second Tuesday of the month (a.k.a. “Patch Tuesday) — and Adobe and Microsoft have issued gobs of security updates for their software. Microsoft’s 11 patch bundles fix more than four-dozen security holes in various Windows versions and Office products — including at least four serious flaws that were publicly disclosed prior to today. Meanwhile, Adobe’s got security updates available for a slew of titles, including Flash Player, Photoshop, Reader and Shockwave.
Four of the vulnerabilities Microsoft fixed today have public exploits, but they do not appear to be used in any active malware campaigns, according to Gill Langston at security vendor Qualys. Perhaps the two most serious flaws likely to impact Windows end users involve vulnerabilities in Microsoft browsers Inter
Qualys
November Patch Tuesday: 53 Vulnerabilities and a Massive Adobe Update | Qualys
blogs_qualys·2017-11-14·CVSS 7.5
[HIGH] November Patch Tuesday: 53 Vulnerabilities and a Massive Adobe Update | Qualys
This November Patch Tuesday is moderate in volume and severity. Microsoft released patches to address 53 unique vulnerabilities, with 25 focused on Remote Code Execution fixes. Windows OS receives 14 patches, while the lion’s share is focused on Browsers, Microsoft Office, and Adobe. According to Microsoft, there do not appear to be any actively attacked vulnerabilities in the wild in this patch release.
Interestingly enough, none of the Windows OS patches are listed as Critical this month, but we do recommend focusing on CVE-2017-11830 and CVE-2017-11847, as they address a Security Feature Bypass, and a Privilege Elevation respectively.
It should also be noted that CVE-2017-11848, CVE-2017-11827, CVE-2017-11883, CVE-2017-8700 have public exploits, but they do not appear to be used in an
http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00024.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007.txthttp://www.debian.org/security/2017/dsa-3999http://www.kb.cert.org/vuls/id/228519http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/101274http://www.securitytracker.com/id/1039572http://www.securitytracker.com/id/1039573http://www.securitytracker.com/id/1039576http://www.securitytracker.com/id/1039577http://www.securitytracker.com/id/1039578http://www.securitytracker.com/id/1039581http://www.securitytracker.com/id/1039585http://www.securitytracker.com/id/1039703http://www.ubuntu.com/usn/USN-3455-1https://access.redhat.com/errata/RHSA-2017:2907https://access.redhat.com/errata/RHSA-2017:2911https://access.redhat.com/security/vulnerabilities/krackshttps://cert-portal.siemens.com/productcert/pdf/ssa-901333.pdfhttps://cert.vde.com/en-us/advisories/vde-2017-003https://cert.vde.com/en-us/advisories/vde-2017-005https://lists.debian.org/debian-lts-announce/2017/12/msg00004.htmlhttps://lists.debian.org/debian-lts-announce/2018/11/msg00015.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-13080https://security.FreeBSD.org/advisories/FreeBSD-SA-17:07.wpa.aschttps://security.gentoo.org/glsa/201711-03https://source.android.com/security/bulletin/2017-11-01https://support.apple.com/HT208219https://support.apple.com/HT208220https://support.apple.com/HT208221https://support.apple.com/HT208222https://support.apple.com/HT208325https://support.apple.com/HT208327https://support.apple.com/HT208334https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03792en_ushttps://support.lenovo.com/us/en/product_security/LEN-17420https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171016-wpahttps://w1.fi/security/2017-1/wpa-packet-number-reuse-with-replayed-messages.txthttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00402.htmlhttps://www.krackattacks.com/http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00024.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007.txthttp://www.debian.org/security/2017/dsa-3999http://www.kb.cert.org/vuls/id/228519http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/101274http://www.securitytracker.com/id/1039572http://www.securitytracker.com/id/1039573http://www.securitytracker.com/id/1039576http://www.securitytracker.com/id/1039577http://www.securitytracker.com/id/1039578http://www.securitytracker.com/id/1039581http://www.securitytracker.com/id/1039585http://www.securitytracker.com/id/1039703http://www.ubuntu.com/usn/USN-3455-1https://access.redhat.com/errata/RHSA-2017:2907https://access.redhat.com/errata/RHSA-2017:2911https://access.redhat.com/security/vulnerabilities/krackshttps://cert-portal.siemens.com/productcert/pdf/ssa-901333.pdfhttps://cert.vde.com/en-us/advisories/vde-2017-003https://cert.vde.com/en-us/advisories/vde-2017-005https://lists.debian.org/debian-lts-announce/2017/12/msg00004.htmlhttps://lists.debian.org/debian-lts-announce/2018/11/msg00015.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-13080https://security.FreeBSD.org/advisories/FreeBSD-SA-17:07.wpa.aschttps://security.gentoo.org/glsa/201711-03https://source.android.com/security/bulletin/2017-11-01https://support.apple.com/HT208219https://support.apple.com/HT208220https://support.apple.com/HT208221https://support.apple.com/HT208222https://support.apple.com/HT208325https://support.apple.com/HT208327https://support.apple.com/HT208334https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03792en_ushttps://support.lenovo.com/us/en/product_security/LEN-17420https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171016-wpahttps://w1.fi/security/2017-1/wpa-packet-number-reuse-with-replayed-messages.txthttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00402.htmlhttps://www.krackattacks.com/
2017-10-17
Published