CVE-2017-13080Reusing a Nonce, Key Pair in Encryption in Alliance Wi-fi Protected Access

Severity
5.3MEDIUMNVD
OSV7.5
EPSS
0.8%
top 25.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateMay 13

Description

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.

CVSS vector

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages11 packages

Debianlinux/linux_kernel< 4.13.13-1+3
NVDopensuse/leap42.2, 42.3+1
NVDw1.fi/hostapd31 versions+30

Also affects: Freebsd 10, 10.4, 11, 11.1, Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.04

🔴Vulnerability Details

7
GHSA
GHSA-jq36-53qv-7v3m: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker withi2022-05-13
OSV
linux-firmware vulnerabilities2017-12-06
OSV
CVE-2017-13080: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker withi2017-10-17
CVEList
CVE-2017-13080: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker withi2017-10-17
OSV
wpa vulnerabilities2017-10-16

📋Vendor Advisories

19
Apple
CVE-2017-13080: Wi-Fi Update for Boot Camp 6.4.02018-07-05
Apple
CVE-2017-13080: macOS High Sierra 10.13.4, Security Update 2018-002 Sierra, and Security Update 2018-002 El Capitan2018-03-29
Apple
CVE-2017-13080: AirPort Base Station Firmware Update 7.7.92017-12-12
Apple
CVE-2017-13080: AirPort Base Station Firmware Update 7.6.92017-12-12
Ubuntu
Linux firmware vulnerabilities2017-12-06

💬Community

3
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 wpa_supplicant: various flaws [fedora-all]2017-10-16
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 hostapd: various flaws [fedora-all]2017-10-16
Bugzilla
CVE-2017-13080 wpa_supplicant: Reinstallation of the group key in the group key handshake2017-09-14
CVE-2017-13080 — MEDIUM severity | cvebase