IM
IronMonkey Threat Research

CVE-2017-13077 MEDIUM

Published: 2017-10-17 | Last Modified: 2026-06-17 | Status: Modified

Description

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.

Additional Descriptions (1)

Wi-Fi Protected Access (WPA y WPA2) permite la reinstalación de la clave temporal (TK) PTK (Pairwise Transient Key) durante la negociación en cuatro pasos, haciendo que un atacante que se sitúe entro del radio responda, descifre o suplante frames.

CVSS Metrics

Base Score: 5.4 (MEDIUM)

AV:A/AC:M/Au:N/C:P/I:P/A:P

Access VectorADJACENT_NETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 5.5

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Primary
en CWE-330

Affected Products

Vendor Product Version Update Type
canonical ubuntu_linux 14.04 <built-in method update of dict object at 0x72a9cc7ed680> Operating System
canonical ubuntu_linux 16.04 <built-in method update of dict object at 0x72a9b0d8d080> Operating System
canonical ubuntu_linux 17.04 <built-in method update of dict object at 0x72a9cc52fa80> Operating System
debian debian_linux 8.0 <built-in method update of dict object at 0x72a9cc52fd80> Operating System
debian debian_linux 9.0 <built-in method update of dict object at 0x72a9cc7edc00> Operating System
freebsd freebsd * <built-in method update of dict object at 0x72a9cc7ef7c0> Operating System
freebsd freebsd 10 <built-in method update of dict object at 0x72a9cc7ee740> Operating System
freebsd freebsd 10.4 <built-in method update of dict object at 0x72a9cc7ec840> Operating System
freebsd freebsd 11 <built-in method update of dict object at 0x72a9cc7ecbc0> Operating System
freebsd freebsd 11.1 <built-in method update of dict object at 0x72a9cc7ef640> Operating System
opensuse leap 42.2 <built-in method update of dict object at 0x72a9b0d8d980> Operating System
opensuse leap 42.3 <built-in method update of dict object at 0x72a9cc52f880> Operating System
redhat enterprise_linux_desktop 7 <built-in method update of dict object at 0x72a9cc725b00> Operating System
redhat enterprise_linux_server 7 <built-in method update of dict object at 0x72a9cc4268c0> Operating System
w1.fi hostapd 0.2.4 <built-in method update of dict object at 0x72a9cc7ed880> Application
w1.fi hostapd 0.2.5 <built-in method update of dict object at 0x72a9b0a74980> Application
w1.fi hostapd 0.2.6 <built-in method update of dict object at 0x72a9cc7ed900> Application
w1.fi hostapd 0.2.8 <built-in method update of dict object at 0x72a9cc52f100> Application
w1.fi hostapd 0.3.7 <built-in method update of dict object at 0x72a9e4187cc0> Application
w1.fi hostapd 0.3.9 <built-in method update of dict object at 0x72a9cc52f280> Application
w1.fi hostapd 0.3.10 <built-in method update of dict object at 0x72a9cc426b40> Application
w1.fi hostapd 0.3.11 <built-in method update of dict object at 0x72a9cc52e680> Application
w1.fi hostapd 0.4.7 <built-in method update of dict object at 0x72a9b0d8d300> Application
w1.fi hostapd 0.4.8 <built-in method update of dict object at 0x72a9cc7efcc0> Application
w1.fi hostapd 0.4.9 <built-in method update of dict object at 0x72a9cc753700> Application
w1.fi hostapd 0.4.10 <built-in method update of dict object at 0x72a9cc52e700> Application
w1.fi hostapd 0.4.11 <built-in method update of dict object at 0x72a9cc7eef40> Application
w1.fi hostapd 0.5.7 <built-in method update of dict object at 0x72a9cc7ecf40> Application
w1.fi hostapd 0.5.8 <built-in method update of dict object at 0x72a9b0d8c180> Application
w1.fi hostapd 0.5.9 <built-in method update of dict object at 0x72a9b0d8c240> Application
w1.fi hostapd 0.5.10 <built-in method update of dict object at 0x72a9b0d8dfc0> Application
w1.fi hostapd 0.5.11 <built-in method update of dict object at 0x72a9b0d8e380> Application
w1.fi hostapd 0.6.8 <built-in method update of dict object at 0x72a9b0d8f280> Application
w1.fi hostapd 0.6.9 <built-in method update of dict object at 0x72a9b0d8cc40> Application
w1.fi hostapd 0.6.10 <built-in method update of dict object at 0x72a9b0d8dbc0> Application
w1.fi hostapd 0.7.3 <built-in method update of dict object at 0x72a9b0d8e0c0> Application
w1.fi hostapd 1.0 <built-in method update of dict object at 0x72a9b0d8e840> Application
w1.fi hostapd 1.1 <built-in method update of dict object at 0x72a9b0d8c680> Application
w1.fi hostapd 2.0 <built-in method update of dict object at 0x72a9b0d8cf80> Application
w1.fi hostapd 2.1 <built-in method update of dict object at 0x72a9b0d8c300> Application
w1.fi hostapd 2.2 <built-in method update of dict object at 0x72a9b0d8f080> Application
w1.fi hostapd 2.3 <built-in method update of dict object at 0x72a9b0d8d780> Application
w1.fi hostapd 2.4 <built-in method update of dict object at 0x72a9b0d8c2c0> Application
w1.fi hostapd 2.5 <built-in method update of dict object at 0x72a9b0d8ea40> Application
w1.fi hostapd 2.6 <built-in method update of dict object at 0x72a9b0d8e540> Application
w1.fi wpa_supplicant 0.2.4 <built-in method update of dict object at 0x72a9b0d8dc00> Application
w1.fi wpa_supplicant 0.2.5 <built-in method update of dict object at 0x72a9b0d8e680> Application
w1.fi wpa_supplicant 0.2.6 <built-in method update of dict object at 0x72a9b0d8e7c0> Application
w1.fi wpa_supplicant 0.2.7 <built-in method update of dict object at 0x72a9b0d8ca80> Application
w1.fi wpa_supplicant 0.2.8 <built-in method update of dict object at 0x72a9b0d8cac0> Application
w1.fi wpa_supplicant 0.3.7 <built-in method update of dict object at 0x72a9b0d8ec00> Application
w1.fi wpa_supplicant 0.3.8 <built-in method update of dict object at 0x72a9b0d8fec0> Application
w1.fi wpa_supplicant 0.3.9 <built-in method update of dict object at 0x72a9b0d8fac0> Application
w1.fi wpa_supplicant 0.3.10 <built-in method update of dict object at 0x72a9b0d8e980> Application
w1.fi wpa_supplicant 0.3.11 <built-in method update of dict object at 0x72a9b0d8e1c0> Application
w1.fi wpa_supplicant 0.4.7 <built-in method update of dict object at 0x72a9cc427ec0> Application
w1.fi wpa_supplicant 0.4.8 <built-in method update of dict object at 0x72a9ccf295c0> Application
w1.fi wpa_supplicant 0.4.9 <built-in method update of dict object at 0x72a9ccf2b5c0> Application
w1.fi wpa_supplicant 0.4.10 <built-in method update of dict object at 0x72a9ccf29400> Application
w1.fi wpa_supplicant 0.4.11 <built-in method update of dict object at 0x72a9cc424280> Application
w1.fi wpa_supplicant 0.5.7 <built-in method update of dict object at 0x72a9ccf29cc0> Application
w1.fi wpa_supplicant 0.5.8 <built-in method update of dict object at 0x72a9ccf28040> Application
w1.fi wpa_supplicant 0.5.9 <built-in method update of dict object at 0x72a9ccf2bec0> Application
w1.fi wpa_supplicant 0.5.10 <built-in method update of dict object at 0x72a9ccf29540> Application
w1.fi wpa_supplicant 0.5.11 <built-in method update of dict object at 0x72a9ccf2bc80> Application
w1.fi wpa_supplicant 0.6.8 <built-in method update of dict object at 0x72a9ccf2b480> Application
w1.fi wpa_supplicant 0.6.9 <built-in method update of dict object at 0x72a9ccf2a200> Application
w1.fi wpa_supplicant 0.6.10 <built-in method update of dict object at 0x72a9ccf2be80> Application
w1.fi wpa_supplicant 0.7.3 <built-in method update of dict object at 0x72a9ccf2b640> Application
w1.fi wpa_supplicant 1.0 <built-in method update of dict object at 0x72a9ccf2bcc0> Application
w1.fi wpa_supplicant 1.1 <built-in method update of dict object at 0x72a9ccf29800> Application
w1.fi wpa_supplicant 2.0 <built-in method update of dict object at 0x72a9ccf29880> Application
w1.fi wpa_supplicant 2.1 <built-in method update of dict object at 0x72a9ccf28cc0> Application
w1.fi wpa_supplicant 2.2 <built-in method update of dict object at 0x72a9ccf28c00> Application
w1.fi wpa_supplicant 2.3 <built-in method update of dict object at 0x72a9ccf28740> Application
w1.fi wpa_supplicant 2.4 <built-in method update of dict object at 0x72a951fecec0> Application
w1.fi wpa_supplicant 2.5 <built-in method update of dict object at 0x72a951fed480> Application
w1.fi wpa_supplicant 2.6 <built-in method update of dict object at 0x72a951fed2c0> Application
suse linux_enterprise_desktop 12 <built-in method update of dict object at 0x72a951fece80> Operating System
suse linux_enterprise_desktop 12 <built-in method update of dict object at 0x72a951fed000> Operating System
suse linux_enterprise_point_of_sale 11 <built-in method update of dict object at 0x72a951feef40> Operating System
suse linux_enterprise_server 11 <built-in method update of dict object at 0x72a951fec400> Operating System
suse linux_enterprise_server 11 <built-in method update of dict object at 0x72a951fee280> Operating System
suse linux_enterprise_server 12 <built-in method update of dict object at 0x72a951fede00> Operating System
suse openstack_cloud 6 <built-in method update of dict object at 0x72a951feeec0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:*
Yes cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:freebsd:freebsd:10:*:*:*:*:*:*:*
Yes cpe:2.3:o:freebsd:freebsd:10.4:*:*:*:*:*:*:*
Yes cpe:2.3:o:freebsd:freebsd:11:*:*:*:*:*:*:*
Yes cpe:2.3:o:freebsd:freebsd:11.1:*:*:*:*:*:*:*
Yes cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:*
Yes cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_desktop:7:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server:7:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:w1.fi:hostapd:0.2.4:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.2.5:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.2.6:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.2.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.3.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.3.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.3.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.3.11:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.4.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.4.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.4.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.4.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.4.11:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.5.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.5.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.5.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.5.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.5.11:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.6.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.6.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.6.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.7.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:1.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:1.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.4:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.5:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.6:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.2.4:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.2.5:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.2.6:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.2.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.2.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.3.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.3.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.3.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.3.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.3.11:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.4.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.4.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.4.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.4.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.4.11:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.5.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.5.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.5.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.5.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.5.11:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.6.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.6.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.6.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.7.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:1.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:1.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.4:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.5:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.6:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:suse:linux_enterprise_desktop:12:sp2:*:*:*:*:*:*
Yes cpe:2.3:o:suse:linux_enterprise_desktop:12:sp3:*:*:*:*:*:*
Yes cpe:2.3:o:suse:linux_enterprise_point_of_sale:11:sp3:*:*:*:*:*:*
Yes cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:ltss:*:*
Yes cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*
Yes cpe:2.3:o:suse:linux_enterprise_server:12:*:*:*:ltss:*:*:*
Yes cpe:2.3:o:suse:openstack_cloud:6:*:*:*:*:*:*:*

References

Notification
Message here