CVE-2017-13081

CWE-323CWE-330CWE-32016 documents11 sources
Severity
5.3MEDIUM
EPSS
0.5%
top 35.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateMay 13

Description

Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.

CVSS vector

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages14 packages

Debianwpa< 2:2.4-1.1+3
Ubuntuwpa< 2.1-0ubuntu1.5+1
Ubuntulinux-firmware< 1.127.24+1
Debianfirmware-nonfree< 20180825-1+3

Also affects: Freebsd 10, 10.4, 11, 11.1, Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.04

🔴Vulnerability Details

5
GHSA
GHSA-gcfj-hpmm-x9xf: Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 8022022-05-13
OSV
linux-firmware vulnerabilities2017-12-06
CVEList
CVE-2017-13081: Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 8022017-10-17
OSV
CVE-2017-13081: Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 8022017-10-17
OSV
wpa vulnerabilities2017-10-16

📋Vendor Advisories

7
Ubuntu
Linux firmware vulnerabilities2017-12-06
Android
CVE-2017-13081: Android Security Bulletin 2017-11-01 CVE: CVE-2017-13081 Severity: HIGH Type: EoP Affected AOSP versions: 52017-11-01
BSD
FreeBSD-SA-17:07.wpa: WPA2 protocol vulnerability2017-10-17
Cisco
Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II2017-10-16
Ubuntu
wpa_supplicant and hostapd vulnerabilities2017-10-16

💬Community

3
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 wpa_supplicant: various flaws [fedora-all]2017-10-16
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 hostapd: various flaws [fedora-all]2017-10-16
Bugzilla
CVE-2017-13081 wpa_supplicant: Reinstallation of the integrity group key in the group key handshake2017-09-14
CVE-2017-13081 (MEDIUM CVSS 5.3) | Wi-Fi Protected Access (WPA and WPA | cvebase.io