CVE-2017-13088

CWE-323CWE-330CWE-32014 documents11 sources
Severity
5.3MEDIUM
EPSS
0.4%
top 40.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateMay 13

Description

Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.

CVSS vector

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages12 packages

Debianwpa< 2:2.4-1.1+3
Ubuntuwpa< 2.1-0ubuntu1.5+1
NVDopensuse/leap42.2, 42.3+1
NVDw1.fi/hostapd31 versions+30

Also affects: Freebsd 10, 10.4, 11, 11.1, Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.04

🔴Vulnerability Details

4
GHSA
GHSA-qvr8-f9g3-wv5x: Wi-Fi Protected Access (WPA and WPA2) that support 8022022-05-13
CVEList
CVE-2017-13088: Wi-Fi Protected Access (WPA and WPA2) that support 8022017-10-17
OSV
CVE-2017-13088: Wi-Fi Protected Access (WPA and WPA2) that support 8022017-10-17
OSV
wpa vulnerabilities2017-10-16

📋Vendor Advisories

6
Android
CVE-2017-13088: Android Security Bulletin 2017-11-01 CVE: CVE-2017-13088 Severity: HIGH Type: EoP Affected AOSP versions: 52017-11-01
BSD
FreeBSD-SA-17:07.wpa: WPA2 protocol vulnerability2017-10-17
Red Hat
wpa_supplicant: reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame2017-10-16
Cisco
Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II2017-10-16
Ubuntu
wpa_supplicant and hostapd vulnerabilities2017-10-16

💬Community

3
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 wpa_supplicant: various flaws [fedora-all]2017-10-16
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 hostapd: various flaws [fedora-all]2017-10-16
Bugzilla
CVE-2017-13088 wpa_supplicant: reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame2017-10-10
CVE-2017-13088 (MEDIUM CVSS 5.3) | Wi-Fi Protected Access (WPA and WPA | cvebase.io