CVE-2017-13081
MEDIUM severity · CVSS 5.3 · CWE-323
5.3CVSS MEDIUM
Summary
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.
Impact & exploitability
Attack vectorAdjacent
Attack complexityHigh
Privileges requiredNone
User interactionNone
Confidentiality impactNone
Integrity impactHigh
Availability impactNone
Exploit probability (EPSS)2%
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products we track (2)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00020.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00023.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00024.htmlAdvisory
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007.txtAdvisory
- http://www.debian.org/security/2017/dsa-3999Advisory
- http://www.kb.cert.org/vuls/id/228519Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.securityfocus.com/bid/101274Advisory