CVE-2017-13086

CWE-323CWE-330CWE-32014 documents11 sources
Severity
6.8MEDIUM
EPSS
0.5%
top 33.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateMay 13

Description

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.

CVSS vector

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 1.6 | Impact: 5.2

Affected Packages12 packages

Debianwpa< 2:2.4-1.1+3
Ubuntuwpa< 2.1-0ubuntu1.5+1
NVDopensuse/leap42.2, 42.3+1
NVDw1.fi/hostapd31 versions+30

Also affects: Freebsd 10, 10.4, 11, 11.1, Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.04

🔴Vulnerability Details

4
GHSA
GHSA-9pwc-v5p9-3c37: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowin2022-05-13
OSV
CVE-2017-13086: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowin2017-10-17
CVEList
CVE-2017-13086: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowin2017-10-17
OSV
wpa vulnerabilities2017-10-16

📋Vendor Advisories

6
Android
CVE-2017-13086: Android Security Bulletin 2017-11-01 CVE: CVE-2017-13086 Severity: HIGH Type: EoP Affected AOSP versions: 52017-11-01
BSD
FreeBSD-SA-17:07.wpa: WPA2 protocol vulnerability2017-10-17
Red Hat
wpa_supplicant: reinstallation of the Tunneled Direct-Link Setup (TDLS) PeerKey (TPK) key in the TDLS handshake2017-10-16
Cisco
Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II2017-10-16
Ubuntu
wpa_supplicant and hostapd vulnerabilities2017-10-16

💬Community

3
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 wpa_supplicant: various flaws [fedora-all]2017-10-16
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 hostapd: various flaws [fedora-all]2017-10-16
Bugzilla
CVE-2017-13086 wpa_supplicant: reinstallation of the Tunneled Direct-Link Setup (TDLS) PeerKey (TPK) key in the TDLS handshake2017-10-10
CVE-2017-13086 (MEDIUM CVSS 6.8) | Wi-Fi Protected Access (WPA and WPA | cvebase.io