Back to search
CVE-2017-13079
Published: Oct 17, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients.
| Vendor | Product | Versions |
|---|---|---|
Wi-Fi Alliance | Wi-Fi Protected Access (WPA and WPA2) | affected WPAaffected WPA2 |
Weaknesses (CWE)
References
1039581
vdb-entry
x_refsource_SECTRACK
101274
vdb-entry
x_refsource_BID
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
x_refsource_CONFIRM
SUSE-SU-2017:2745
vendor-advisory
x_refsource_SUSE
DSA-3999
vendor-advisory
x_refsource_DEBIAN
1039578
vdb-entry
x_refsource_SECTRACK
https://access.redhat.com/security/vulnerabilities/kracks
x_refsource_CONFIRM
20171016 Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II
vendor-advisory
x_refsource_CISCO
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007.txt
x_refsource_CONFIRM
1039577
vdb-entry
x_refsource_SECTRACK
openSUSE-SU-2017:2755
vendor-advisory
x_refsource_SUSE
https://source.android.com/security/bulletin/2017-11-01
x_refsource_CONFIRM
GLSA-201711-03
vendor-advisory
x_refsource_GENTOO
https://support.lenovo.com/us/en/product_security/LEN-17420
x_refsource_CONFIRM
FreeBSD-SA-17:07
vendor-advisory
x_refsource_FREEBSD
https://www.krackattacks.com/
x_refsource_MISC
1039573
vdb-entry
x_refsource_SECTRACK
SUSE-SU-2017:2752
vendor-advisory
x_refsource_SUSE
1039576
vdb-entry
x_refsource_SECTRACK
1039585
vdb-entry
x_refsource_SECTRACK
VU#228519
third-party-advisory
x_refsource_CERT-VN
[debian-lts-announce] 20181113 [SECURITY] [DLA 1573-1] firmware-nonfree security update
mailing-list
x_refsource_MLIST
https://cert-portal.siemens.com/productcert/pdf/ssa-901333.pdf
x_refsource_CONFIRM
https://cert.vde.com/en-us/advisories/vde-2017-005
x_refsource_CONFIRM
USN-3455-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now