CVE-2017-13084
published 2017-10-17CVE-2017-13084: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an…
PriorityP434medium6.8CVSS 3.0
AVAACHPRNUINSUCHIHAN
EPSS
2.21%
80.6th percentile
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
Affected
85 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | wpa | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_point_of_sale | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | openstack_cloud | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.4MEDIUMAV:A/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_cisco6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mxrv-cp62-8842: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, al
ghsa_unreviewed·2022-05-13
CVE-2017-13084 [MEDIUM] CWE-323 GHSA-mxrv-cp62-8842: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, al
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
OSV
CVE-2017-13084: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, al
osv·2017-10-17·CVSS 6.8
CVE-2017-13084 [MEDIUM] CVE-2017-13084: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, al
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
CISA ICS
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update E)
cisa_ics·2018-04-24
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update E)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update E)
Last RevisedJune 19, 2019
Alert CodeICSA-17-318-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.8
- ATTENTION: Exploitable remotely/low skill level to exploit/public exploits are available.
- Vendor: Siemens
- Equipment: SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products
- Vulnerabilities: Security Features
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the updated advisory titled ICSA-17-318-01 Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update D) that was published April 24,
CISA ICS
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update F)
cisa_ics·2018-04-24
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update F)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update F)
Last RevisedApril 09, 2019
Alert CodeICSA-17-318-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.8
- ATTENTION: Exploitable remotely/low skill level to exploit/public exploits are available.
- Vendor: Siemens
- Equipment: SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products
- Vulnerabilities: Security Features
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the updated advisory titled ICSA-17-318-01 Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update D) that was published April 24
CISA ICS
ABB TropOS (Update A)
cisa_ics·2017-11-14
ABB TropOS (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB TropOS (Update A)
Last RevisedFebruary 15, 2018
Alert CodeICSA-17-318-02A
## CVSS v3 6.8
Vendor: ABB
Equipment: TropOS
Vulnerabilities: Security Features
## UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-17-318-02 ABB TropOS that was published November 14, 2017, on the NCCIC/ICS-CERT website.
## AFFECTED PRODUCTS
ABB reports that the key reinstallation attacks (KRACK) potentially affect all TropOS broadband mesh routers and bridges operating on Mesh OS release 8.5.2 or prior.
## IMPACT
Successful exploitation of these vul
Cisco
Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
vendor_cisco·2017-10-16·CVSS 6.8
CVE-2017-13077 [MEDIUM] CWE-320 Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
On October 16, 2017, a research paper with the title “Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2” was made publicly available. This paper discusses seven vulnerabilities affecting session key negotiation in both the Wi-Fi Protected Access (WPA) and the Wi-Fi Protected Access II (WPA2) protocols. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point. Additional research also led to the discovery of three additional vulnerabilities (not discussed in the original paper) affecting wireless supplicant supporting either the 802.11z (Extensions to Direct-Link Setup) standard or the 802.11v (
Red Hat
wpa_supplicant: reinstallation of the STK key in the PeerKey handshake
vendor_redhat·2017-10-16·CVSS 6.8
CVE-2017-13084 [MEDIUM] CWE-323 wpa_supplicant: reinstallation of the STK key in the PeerKey handshake
wpa_supplicant: reinstallation of the STK key in the PeerKey handshake
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
Statement: This issue did not affect the versions of wpa_supplicant as shipped with Red Hat Enterprise Linux 5, 6, and 7, as wpa_supplicant's implementation of the PeerKey handshake mechanism is incomplete and does not allow the installation of a key into the driver.
Package: wpa_supplicant (Red Hat Enterprise Linux 5) - Not affected
Package: wpa_supplicant (Red Hat Enterprise Linux 6) - Not affected
Package: wpa_supplicant (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2017-13084: wpa - Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-St...
vendor_debian·2017·CVSS 6.8
CVE-2017-13084 [MEDIUM] CVE-2017-13084: wpa - Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-St...
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Cisco
Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
vendor_cisco·CVSS 3.0
CVE-2017-13084 Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
CVE-2017-13084: Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
On October 16, 2017, a research paper with the title “Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2” was made publicly available. This paper discusses seven vulnerabilities affecting session key negotiation in both the Wi-Fi Protected Access (WPA) and the Wi-Fi Protected Access II (WPA2) protocols. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point. Additional research also led to the discovery of three additional vulnerabilities (not discussed in the original paper) affecting wireless supplicant supporting either the 802.11z (Extensions to Direct-Link Setup) standard o
No detection rules found.
No public exploits indexed.
HackerOne
Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse
hackerone·2017-11-03·CVSS 6.8
CVE-2017-13077 [MEDIUM] Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse
Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse
Full background information is at [krackattacks.com](https://www.krackattacks.com) and all detailed information can be found in our [research paper](https://papers.mathyvanhoef.com/ccs2017.pdf).
# Key Reinstallation Attack: 4-way handshake example
We use the 4-way handshake to illustrate the idea behind key reinstallation attacks (CVE-2017-13077).
Note that in practice, all protected Wi-Fi network rely on the 4-way handshake to derive a fresh session key (PTK) from some shared secret.
### Step 1. Channel-based man-in-the-middle and initial handshake messages:
* The adversary clones the access point (AP) on a different channel. Say the real AP is on channel 6, and it will be cloned on channel 1.
* The adversary uses Chann
Bugzilla
CVE-2017-13084 wpa_supplicant: reinstallation of the STK key in the PeerKey handshake
bugzilla·2017-10-10·CVSS 6.8
CVE-2017-13084 [MEDIUM] CVE-2017-13084 wpa_supplicant: reinstallation of the STK key in the PeerKey handshake
CVE-2017-13084 wpa_supplicant: reinstallation of the STK key in the PeerKey handshake
Wi-Fi Protected Access II (WPA2) handshake traffic can be manipulated to induce nonce and session key reuse, resulting in key reinstallation by a victim wireless access point (AP) or client. After establishing a man-in-the-middle position between an AP and client, an attacker can selectively manipulate the timing and transmission of messages in the WPA2 PeerKey handshake, resulting in out-of-sequence reception or retransmission of messages.
An attacker within the wireless communications range of an affected AP and client may leverage these vulnerabilities to conduct attacks that are dependent on the data confidentiality protocol being used. Attacks may include arbitrary packet decryption and injection,
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007.txthttp://www.kb.cert.org/vuls/id/228519http://www.securityfocus.com/bid/101274http://www.securitytracker.com/id/1039576http://www.securitytracker.com/id/1039577http://www.securitytracker.com/id/1039581https://access.redhat.com/security/vulnerabilities/krackshttps://cert-portal.siemens.com/productcert/pdf/ssa-901333.pdfhttps://security.gentoo.org/glsa/201711-03https://support.lenovo.com/us/en/product_security/LEN-17420https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171016-wpahttps://w1.fi/security/2017-1/wpa-packet-number-reuse-with-replayed-messages.txthttps://www.krackattacks.com/http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007.txthttp://www.kb.cert.org/vuls/id/228519http://www.securityfocus.com/bid/101274http://www.securitytracker.com/id/1039576http://www.securitytracker.com/id/1039577http://www.securitytracker.com/id/1039581https://access.redhat.com/security/vulnerabilities/krackshttps://cert-portal.siemens.com/productcert/pdf/ssa-901333.pdfhttps://security.gentoo.org/glsa/201711-03https://support.lenovo.com/us/en/product_security/LEN-17420https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171016-wpahttps://w1.fi/security/2017-1/wpa-packet-number-reuse-with-replayed-messages.txthttps://www.krackattacks.com/
2017-10-17
Published