IM
IronMonkey Threat Research

CVE-2017-13088 MEDIUM

Published: 2017-10-17 | Last Modified: 2026-06-17 | Status: Modified

Description

Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.

Additional Descriptions (1)

Wi-Fi Protected Access (WPA y WPA2) que soporte IEEE 802.11v permite la reinstalación de la clave temporal GTK (Integrity Group Temporal Key) cuando se procesa un frame Wireless Network Management (WNM) Sleep Mode Response, haciendo que un atacante que se sitúe dentro del radio reproduzca frames desde los puntos de acceso hasta los clientes.

CVSS Metrics

Base Score: 2.9 (LOW)

AV:A/AC:M/Au:N/C:N/I:P/A:N

Access VectorADJACENT_NETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactPARTIAL
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 5.5

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-323
[email protected] Primary
en CWE-330

Affected Products

Vendor Product Version Update Type
canonical ubuntu_linux 14.04 <built-in method update of dict object at 0x72a9cc67ba80> Operating System
canonical ubuntu_linux 16.04 <built-in method update of dict object at 0x72a9cc67bb00> Operating System
canonical ubuntu_linux 17.04 <built-in method update of dict object at 0x72a9b0c6cec0> Operating System
debian debian_linux 8.0 <built-in method update of dict object at 0x72a9cd06e3c0> Operating System
debian debian_linux 9.0 <built-in method update of dict object at 0x72a9cc678300> Operating System
freebsd freebsd * <built-in method update of dict object at 0x72a9cc6783c0> Operating System
freebsd freebsd 10 <built-in method update of dict object at 0x72a9cc523f40> Operating System
freebsd freebsd 10.4 <built-in method update of dict object at 0x72a9cc67ba40> Operating System
freebsd freebsd 11 <built-in method update of dict object at 0x72a9cc76e740> Operating System
freebsd freebsd 11.1 <built-in method update of dict object at 0x72a9cc678340> Operating System
opensuse leap 42.2 <built-in method update of dict object at 0x72a9b0c6e6c0> Operating System
opensuse leap 42.3 <built-in method update of dict object at 0x72a9cc678e40> Operating System
redhat enterprise_linux_desktop 7 <built-in method update of dict object at 0x72a9b0c6ca40> Operating System
redhat enterprise_linux_server 7 <built-in method update of dict object at 0x72a9b0c6fe80> Operating System
w1.fi hostapd 0.2.4 <built-in method update of dict object at 0x72a9cc76fe40> Application
w1.fi hostapd 0.2.5 <built-in method update of dict object at 0x72a9b0c6df80> Application
w1.fi hostapd 0.2.6 <built-in method update of dict object at 0x72a9cc67a780> Application
w1.fi hostapd 0.2.8 <built-in method update of dict object at 0x72a9cc76dd40> Application
w1.fi hostapd 0.3.7 <built-in method update of dict object at 0x72a9b0c6d7c0> Application
w1.fi hostapd 0.3.9 <built-in method update of dict object at 0x72a9cc523e40> Application
w1.fi hostapd 0.3.10 <built-in method update of dict object at 0x72a9cd06c7c0> Application
w1.fi hostapd 0.3.11 <built-in method update of dict object at 0x72a9cc678ac0> Application
w1.fi hostapd 0.4.7 <built-in method update of dict object at 0x72a9b0c6fcc0> Application
w1.fi hostapd 0.4.8 <built-in method update of dict object at 0x72a9cc678500> Application
w1.fi hostapd 0.4.9 <built-in method update of dict object at 0x72a9b0b6b6c0> Application
w1.fi hostapd 0.4.10 <built-in method update of dict object at 0x72a9cc76ef00> Application
w1.fi hostapd 0.4.11 <built-in method update of dict object at 0x72a9b0b6bf00> Application
w1.fi hostapd 0.5.7 <built-in method update of dict object at 0x72a9b0c6fe00> Application
w1.fi hostapd 0.5.8 <built-in method update of dict object at 0x72a9b0c6d8c0> Application
w1.fi hostapd 0.5.9 <built-in method update of dict object at 0x72a9b0c6d700> Application
w1.fi hostapd 0.5.10 <built-in method update of dict object at 0x72a9b0c6e5c0> Application
w1.fi hostapd 0.5.11 <built-in method update of dict object at 0x72a9b0c6d1c0> Application
w1.fi hostapd 0.6.8 <built-in method update of dict object at 0x72a9b0c6cbc0> Application
w1.fi hostapd 0.6.9 <built-in method update of dict object at 0x72a9b0c6d680> Application
w1.fi hostapd 0.6.10 <built-in method update of dict object at 0x72a9b0c6f380> Application
w1.fi hostapd 0.7.3 <built-in method update of dict object at 0x72a9b0c6f700> Application
w1.fi hostapd 1.0 <built-in method update of dict object at 0x72a9b0c6fec0> Application
w1.fi hostapd 1.1 <built-in method update of dict object at 0x72a9b0c6e880> Application
w1.fi hostapd 2.0 <built-in method update of dict object at 0x72a9b0c6d6c0> Application
w1.fi hostapd 2.1 <built-in method update of dict object at 0x72a9b0c6cac0> Application
w1.fi hostapd 2.2 <built-in method update of dict object at 0x72a9b0c6c4c0> Application
w1.fi hostapd 2.3 <built-in method update of dict object at 0x72a9b0c6cc40> Application
w1.fi hostapd 2.4 <built-in method update of dict object at 0x72a999779a00> Application
w1.fi hostapd 2.5 <built-in method update of dict object at 0x72a99977b640> Application
w1.fi hostapd 2.6 <built-in method update of dict object at 0x72a999779c40> Application
w1.fi wpa_supplicant 0.2.4 <built-in method update of dict object at 0x72a999779580> Application
w1.fi wpa_supplicant 0.2.5 <built-in method update of dict object at 0x72a99977b480> Application
w1.fi wpa_supplicant 0.2.6 <built-in method update of dict object at 0x72a99977a740> Application
w1.fi wpa_supplicant 0.2.7 <built-in method update of dict object at 0x72a99977b040> Application
w1.fi wpa_supplicant 0.2.8 <built-in method update of dict object at 0x72a99977ac80> Application
w1.fi wpa_supplicant 0.3.7 <built-in method update of dict object at 0x72a99977b340> Application
w1.fi wpa_supplicant 0.3.8 <built-in method update of dict object at 0x72a99977aec0> Application
w1.fi wpa_supplicant 0.3.9 <built-in method update of dict object at 0x72a999778fc0> Application
w1.fi wpa_supplicant 0.3.10 <built-in method update of dict object at 0x72a9997791c0> Application
w1.fi wpa_supplicant 0.3.11 <built-in method update of dict object at 0x72a999778540> Application
w1.fi wpa_supplicant 0.4.7 <built-in method update of dict object at 0x72a9cd06ee00> Application
w1.fi wpa_supplicant 0.4.8 <built-in method update of dict object at 0x72a963c6ab00> Application
w1.fi wpa_supplicant 0.4.9 <built-in method update of dict object at 0x72a963c6a380> Application
w1.fi wpa_supplicant 0.4.10 <built-in method update of dict object at 0x72a963c69400> Application
w1.fi wpa_supplicant 0.4.11 <built-in method update of dict object at 0x72a9cd06e580> Application
w1.fi wpa_supplicant 0.5.7 <built-in method update of dict object at 0x72a963c6bc40> Application
w1.fi wpa_supplicant 0.5.8 <built-in method update of dict object at 0x72a999778dc0> Application
w1.fi wpa_supplicant 0.5.9 <built-in method update of dict object at 0x72a963c68180> Application
w1.fi wpa_supplicant 0.5.10 <built-in method update of dict object at 0x72a963c6a100> Application
w1.fi wpa_supplicant 0.5.11 <built-in method update of dict object at 0x72a963c6b640> Application
w1.fi wpa_supplicant 0.6.8 <built-in method update of dict object at 0x72a963c693c0> Application
w1.fi wpa_supplicant 0.6.9 <built-in method update of dict object at 0x72a963c686c0> Application
w1.fi wpa_supplicant 0.6.10 <built-in method update of dict object at 0x72a963c69d40> Application
w1.fi wpa_supplicant 0.7.3 <built-in method update of dict object at 0x72a963c6b700> Application
w1.fi wpa_supplicant 1.0 <built-in method update of dict object at 0x72a963c690c0> Application
w1.fi wpa_supplicant 1.1 <built-in method update of dict object at 0x72a963c6a500> Application
w1.fi wpa_supplicant 2.0 <built-in method update of dict object at 0x72a963c69c00> Application
w1.fi wpa_supplicant 2.1 <built-in method update of dict object at 0x72a963c6a4c0> Application
w1.fi wpa_supplicant 2.2 <built-in method update of dict object at 0x72a963c6af80> Application
w1.fi wpa_supplicant 2.3 <built-in method update of dict object at 0x72a963c6b3c0> Application
w1.fi wpa_supplicant 2.4 <built-in method update of dict object at 0x72a9cd084100> Application
w1.fi wpa_supplicant 2.5 <built-in method update of dict object at 0x72a9cd086f40> Application
w1.fi wpa_supplicant 2.6 <built-in method update of dict object at 0x72a9cd085480> Application
suse linux_enterprise_desktop 12 <built-in method update of dict object at 0x72a9cd086a40> Operating System
suse linux_enterprise_desktop 12 <built-in method update of dict object at 0x72a9cd087100> Operating System
suse linux_enterprise_point_of_sale 11 <built-in method update of dict object at 0x72a9cd084680> Operating System
suse linux_enterprise_server 11 <built-in method update of dict object at 0x72a9cd084d80> Operating System
suse linux_enterprise_server 11 <built-in method update of dict object at 0x72a9cd087d80> Operating System
suse linux_enterprise_server 12 <built-in method update of dict object at 0x72a9cd084840> Operating System
suse openstack_cloud 6 <built-in method update of dict object at 0x72a9cd084080> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:*
Yes cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:freebsd:freebsd:10:*:*:*:*:*:*:*
Yes cpe:2.3:o:freebsd:freebsd:10.4:*:*:*:*:*:*:*
Yes cpe:2.3:o:freebsd:freebsd:11:*:*:*:*:*:*:*
Yes cpe:2.3:o:freebsd:freebsd:11.1:*:*:*:*:*:*:*
Yes cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:*
Yes cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_desktop:7:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server:7:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:w1.fi:hostapd:0.2.4:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.2.5:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.2.6:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.2.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.3.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.3.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.3.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.3.11:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.4.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.4.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.4.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.4.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.4.11:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.5.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.5.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.5.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.5.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.5.11:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.6.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.6.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.6.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:0.7.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:1.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:1.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.4:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.5:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:hostapd:2.6:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.2.4:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.2.5:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.2.6:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.2.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.2.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.3.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.3.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.3.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.3.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.3.11:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.4.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.4.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.4.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.4.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.4.11:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.5.7:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.5.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.5.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.5.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.5.11:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.6.8:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.6.9:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.6.10:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:0.7.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:1.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:1.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.4:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.5:*:*:*:*:*:*:*
Yes cpe:2.3:a:w1.fi:wpa_supplicant:2.6:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:suse:linux_enterprise_desktop:12:sp2:*:*:*:*:*:*
Yes cpe:2.3:o:suse:linux_enterprise_desktop:12:sp3:*:*:*:*:*:*
Yes cpe:2.3:o:suse:linux_enterprise_point_of_sale:11:sp3:*:*:*:*:*:*
Yes cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:ltss:*:*
Yes cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*
Yes cpe:2.3:o:suse:linux_enterprise_server:12:*:*:*:ltss:*:*:*
Yes cpe:2.3:o:suse:openstack_cloud:6:*:*:*:*:*:*:*

References

Notification
Message here