CVE-2017-13088
published 2017-10-17CVE-2017-13088: Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network…
PriorityP430medium5.3CVSS 3.0
AVAACHPRNUINSUCNIHAN
EPSS
1.81%
76.1th percentile
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
Affected
92 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | wpa | < wpa 2:2.4-1.1 (bookworm) | wpa 2:2.4-1.1 (bookworm) |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| android | — | — | |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_point_of_sale | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | openstack_cloud | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_cisco6.8MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update E)
cisa_ics·2018-04-24
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update E)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update E)
Last RevisedJune 19, 2019
Alert CodeICSA-17-318-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.8
- ATTENTION: Exploitable remotely/low skill level to exploit/public exploits are available.
- Vendor: Siemens
- Equipment: SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products
- Vulnerabilities: Security Features
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the updated advisory titled ICSA-17-318-01 Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update D) that was published April 24,
CISA ICS
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update F)
cisa_ics·2018-04-24
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update F)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update F)
Last RevisedApril 09, 2019
Alert CodeICSA-17-318-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.8
- ATTENTION: Exploitable remotely/low skill level to exploit/public exploits are available.
- Vendor: Siemens
- Equipment: SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products
- Vulnerabilities: Security Features
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the updated advisory titled ICSA-17-318-01 Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update D) that was published April 24
CISA ICS
PEPPERL+FUCHS/ecom instruments WLAN Capable Devices using the WPA2 Protocol
cisa_ics·2017-12-19
PEPPERL+FUCHS/ecom instruments WLAN Capable Devices using the WPA2 Protocol
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
PEPPERL+FUCHS/ecom instruments WLAN Capable Devices using the WPA2 Protocol
Last RevisedDecember 19, 2017
Alert CodeICSA-17-353-02
## CVSS v3 8.1
ATTENTION: Low skill level is needed to exploit. Public exploits are available.
Vendor: PEPPERL+FUCHS/ecom instruments
Equipment: WLAN capable devices using the WPA2 Protocol
Vulnerabilities: Reusing a Nonce
## AFFECTED PRODUCTS
PEPPERL+FUCHS/ecom instruments reports that these vulnerabilities affect all versions of the following WLAN capable devices using the WPA2 Protocol:
- Tab-Ex 01,
- Ex-Handy 09,
- Ex-Handy 209,
- Smart-
CISA ICS
ABB TropOS (Update A)
cisa_ics·2017-11-14
ABB TropOS (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB TropOS (Update A)
Last RevisedFebruary 15, 2018
Alert CodeICSA-17-318-02A
## CVSS v3 6.8
Vendor: ABB
Equipment: TropOS
Vulnerabilities: Security Features
## UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-17-318-02 ABB TropOS that was published November 14, 2017, on the NCCIC/ICS-CERT website.
## AFFECTED PRODUCTS
ABB reports that the key reinstallation attacks (KRACK) potentially affect all TropOS broadband mesh routers and bridges operating on Mesh OS release 8.5.2 or prior.
## IMPACT
Successful exploitation of these vul
Android
CVE-2017-13088: Android Security Bulletin 2017-11-01
CVE: CVE-2017-13088
Severity: HIGH
Type: EoP
Affected AOSP versions: 5
vendor_android·2017-11-01·CVSS 5.3
CVE-2017-13088 [MEDIUM] CVE-2017-13088: Android Security Bulletin 2017-11-01
CVE: CVE-2017-13088
Severity: HIGH
Type: EoP
Affected AOSP versions: 5
Android Security Bulletin 2017-11-01
CVE: CVE-2017-13088
Severity: HIGH
Type: EoP
Affected AOSP versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0
References: A-67737262
BSD
FreeBSD-SA-17:07.wpa: WPA2 protocol vulnerability
bsd_advisories·2017-10-17·CVSS 6.8
CVE-2017-13077 [MEDIUM] FreeBSD-SA-17:07.wpa: WPA2 protocol vulnerability
FreeBSD-SA-17:07.wpa Security Advisory
The FreeBSD Project
Topic: WPA2 protocol vulnerability
Category: contrib
Module: wpa
Announced: 2017-10-16
Credits: Mathy Vanhoef
Affects: All supported versions of FreeBSD.
Corrected: 2017-10-17 17:30:18 UTC (stable/11, 11.1-STABLE)
2017-10-17 17:57:18 UTC (releng/11.1, 11.1-RELEASE-p2)
2017-10-17 17:56:03 UTC (releng/11.0, 11.0-RELEASE-p13)
2017-10-19 03:18:22 UTC (stable/10, 10.4-STABLE)
2017-10-19 03:20:17 UTC (releng/10.4, 10.4-RELEASE-p1)
2017-10-19 03:19:42 UTC (releng/10.3, 10.3-RELEASE-p22)
CVE Name: CVE-2017-13077, CVE-2017-13078, CVE-2017-13079,
CVE-2017-13080, CVE-2017-13081, CVE-2017-13082,
CVE-2017-13086, CVE-2017-13087, CVE-2017-13088
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields
Red Hat
wpa_supplicant: reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame
vendor_redhat·2017-10-16·CVSS 5.3
CVE-2017-13088 [MEDIUM] CWE-323 wpa_supplicant: reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame
wpa_supplicant: reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
A new exploitation technique called key reinstallation attacks (KRACK) affecting WPA2 has been discovered. A remote attacker within Wi-Fi range could exploit this attack to decrypt Wi-Fi traffic or possibly inject forged Wi-Fi packets by reinstalling a previously used integrity group key (IGTK) during a Wireless Network Management (WNM) Sleep Mode handshake.
St
Cisco
Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
vendor_cisco·2017-10-16·CVSS 6.8
CVE-2017-13077 [MEDIUM] CWE-320 Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
On October 16, 2017, a research paper with the title “Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2” was made publicly available. This paper discusses seven vulnerabilities affecting session key negotiation in both the Wi-Fi Protected Access (WPA) and the Wi-Fi Protected Access II (WPA2) protocols. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point. Additional research also led to the discovery of three additional vulnerabilities (not discussed in the original paper) affecting wireless supplicant supporting either the 802.11z (Extensions to Direct-Link Setup) standard or the 802.11v (
Ubuntu
wpa_supplicant and hostapd vulnerabilities
vendor_ubuntu·2017-10-16·CVSS 7.5
CVE-2016-4476 [HIGH] wpa_supplicant and hostapd vulnerabilities
Title: wpa_supplicant and hostapd vulnerabilities
Summary: Several security issues were fixed in wpa_supplicant.
Mathy Vanhoef discovered that wpa_supplicant and hostapd incorrectly
handled WPA2. A remote attacker could use this issue with key
reinstallation attacks to obtain sensitive information. (CVE-2017-13077,
CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081,
CVE-2017-13082, CVE-2017-13086, CVE-2017-13087, CVE-2017-13088)
Imre Rad discovered that wpa_supplicant and hostapd incorrectly handled
invalid characters in passphrase parameters. A remote attacker could use
this issue to cause a denial of service. (CVE-2016-4476)
Imre Rad discovered that wpa_supplicant and hostapd incorrectly handled
invalid characters in passphrase parameters. A local attacker could use
this
Debian
CVE-2017-13088: wpa - Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation...
vendor_debian·2017·CVSS 5.3
CVE-2017-13088 [MEDIUM] CVE-2017-13088: wpa - Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation...
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
Scope: local
bookworm: resolved (fixed in 2:2.4-1.1)
bullseye: resolved (fixed in 2:2.4-1.1)
forky: resolved (fixed in 2:2.4-1.1)
sid: resolved (fixed in 2:2.4-1.1)
trixie: resolved (fixed in 2:2.4-1.1)
Cisco
Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
vendor_cisco·CVSS 3.0
CVE-2017-13088 Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
CVE-2017-13088: Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
On October 16, 2017, a research paper with the title “Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2” was made publicly available. This paper discusses seven vulnerabilities affecting session key negotiation in both the Wi-Fi Protected Access (WPA) and the Wi-Fi Protected Access II (WPA2) protocols. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point. Additional research also led to the discovery of three additional vulnerabilities (not discussed in the original paper) affecting wireless supplicant supporting either the 802.11z (Extensions to Direct-Link Setup) standard o
GHSA
GHSA-qvr8-f9g3-wv5x: Wi-Fi Protected Access (WPA and WPA2) that support 802
ghsa_unreviewed·2022-05-13
CVE-2017-13088 [MEDIUM] CWE-323 GHSA-qvr8-f9g3-wv5x: Wi-Fi Protected Access (WPA and WPA2) that support 802
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
OSV
CVE-2017-13088: Wi-Fi Protected Access (WPA and WPA2) that support 802
osv·2017-10-17·CVSS 5.3
CVE-2017-13088 [MEDIUM] CVE-2017-13088: Wi-Fi Protected Access (WPA and WPA2) that support 802
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
OSV
wpa vulnerabilities
osv·2017-10-16·CVSS 7.5
CVE-2017-13077 [HIGH] wpa vulnerabilities
wpa vulnerabilities
Mathy Vanhoef discovered that wpa_supplicant and hostapd incorrectly
handled WPA2. A remote attacker could use this issue with key
reinstallation attacks to obtain sensitive information. (CVE-2017-13077,
CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081,
CVE-2017-13082, CVE-2017-13086, CVE-2017-13087, CVE-2017-13088)
Imre Rad discovered that wpa_supplicant and hostapd incorrectly handled
invalid characters in passphrase parameters. A remote attacker could use
this issue to cause a denial of service. (CVE-2016-4476)
Imre Rad discovered that wpa_supplicant and hostapd incorrectly handled
invalid characters in passphrase parameters. A local attacker could use
this issue to cause a denial of service, or possibly execute arbitrary
code. (CVE-2016-4477)
No detection rules found.
No public exploits indexed.
HackerOne
Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse
hackerone·2017-11-03·CVSS 6.8
CVE-2017-13077 [MEDIUM] Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse
Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse
Full background information is at [krackattacks.com](https://www.krackattacks.com) and all detailed information can be found in our [research paper](https://papers.mathyvanhoef.com/ccs2017.pdf).
# Key Reinstallation Attack: 4-way handshake example
We use the 4-way handshake to illustrate the idea behind key reinstallation attacks (CVE-2017-13077).
Note that in practice, all protected Wi-Fi network rely on the 4-way handshake to derive a fresh session key (PTK) from some shared secret.
### Step 1. Channel-based man-in-the-middle and initial handshake messages:
* The adversary clones the access point (AP) on a different channel. Say the real AP is on channel 6, and it will be cloned on channel 1.
* The adversary uses Chann
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 wpa_supplicant: various flaws [fedora-all]
bugzilla·2017-10-16·CVSS 6.8
CVE-2017-13077 [MEDIUM] CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 wpa_supplicant: various flaws [fedora-all]
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 wpa_supplicant: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in th
Bugzilla
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 hostapd: various flaws [fedora-all]
bugzilla·2017-10-16·CVSS 6.8
CVE-2017-13077 [MEDIUM] CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 hostapd: various flaws [fedora-all]
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 hostapd: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM c
Bugzilla
CVE-2017-13088 wpa_supplicant: reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame
bugzilla·2017-10-10·CVSS 5.3
CVE-2017-13088 [MEDIUM] CVE-2017-13088 wpa_supplicant: reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame
CVE-2017-13088 wpa_supplicant: reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame
Wi-Fi Protected Access II (WPA2) handshake traffic can be manipulated to induce nonce and session key reuse, resulting in key reinstallation by a victim wireless access point (AP) or client. After establishing a man-in-the-middle position between an AP and client, an attacker can selectively manipulate the timing and transmission of messages in the WPA2 Wireless Network Management (WNM) Sleep Mode handshake, resulting in out-of-sequence reception or retransmission of messages.
An attacker within the wireless communications range of an affected AP and client may leverage these vulnerabilities to conduct attacks that are dependent on
http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00024.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007.txthttp://www.debian.org/security/2017/dsa-3999http://www.kb.cert.org/vuls/id/228519http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/101274http://www.securitytracker.com/id/1039573http://www.securitytracker.com/id/1039576http://www.securitytracker.com/id/1039577http://www.securitytracker.com/id/1039578http://www.securitytracker.com/id/1039581http://www.ubuntu.com/usn/USN-3455-1https://access.redhat.com/errata/RHSA-2017:2907https://access.redhat.com/security/vulnerabilities/krackshttps://cert-portal.siemens.com/productcert/pdf/ssa-901333.pdfhttps://cert.vde.com/en-us/advisories/vde-2017-005https://security.FreeBSD.org/advisories/FreeBSD-SA-17:07.wpa.aschttps://security.gentoo.org/glsa/201711-03https://source.android.com/security/bulletin/2017-11-01https://support.lenovo.com/us/en/product_security/LEN-17420https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171016-wpahttps://w1.fi/security/2017-1/wpa-packet-number-reuse-with-replayed-messages.txthttps://www.krackattacks.com/http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00024.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007.txthttp://www.debian.org/security/2017/dsa-3999http://www.kb.cert.org/vuls/id/228519http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/101274http://www.securitytracker.com/id/1039573http://www.securitytracker.com/id/1039576http://www.securitytracker.com/id/1039577http://www.securitytracker.com/id/1039578http://www.securitytracker.com/id/1039581http://www.ubuntu.com/usn/USN-3455-1https://access.redhat.com/errata/RHSA-2017:2907https://access.redhat.com/security/vulnerabilities/krackshttps://cert-portal.siemens.com/productcert/pdf/ssa-901333.pdfhttps://cert.vde.com/en-us/advisories/vde-2017-005https://security.FreeBSD.org/advisories/FreeBSD-SA-17:07.wpa.aschttps://security.gentoo.org/glsa/201711-03https://source.android.com/security/bulletin/2017-11-01https://support.lenovo.com/us/en/product_security/LEN-17420https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171016-wpahttps://w1.fi/security/2017-1/wpa-packet-number-reuse-with-replayed-messages.txthttps://www.krackattacks.com/
2017-10-17
Published