Vulnerability CVE-2017-13088


Published: 2017-10-17

Description:
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.

Type:

CWE-254

(Security Features)

Vendor: Debian
Product: Debian linux 
Version: 9.0; 8.0;
Vendor: Redhat
Product: Enterprise linux server 
Version: 7;
Product: Enterprise linux desktop 
Version: 7;
Vendor: SUSE
Product: Openstack cloud 
Version: 6;
Product: Linux enterprise server 
Version: 12; 11;
Product: Linux enterprise desktop 
Version: 12;
Product: Linux enterprise point of sale 
Version: 11;
Vendor: Opensuse
Product: LEAP 
Version: 42.3; 42.2;
Vendor: W1.fi
Product: Wpa supplicant 
Version:
2.6
2.5
2.4
2.3
2.2
2.1
2.0
1.1
1.0
0.7.3
0.6.9
0.6.8
0.6.10
0.5.9
0.5.8
0.5.7
0.5.11
0.5.10
0.4.9
0.4.8
0.4.7
0.4.11
0.4.10
0.3.9
0.3.8
0.3.7
0.3.11
0.3.10
0.2.8
0.2.7
0.2.6
0.2.5
0.2.4
Product: Hostapd 
Version:
2.6
2.5
2.4
2.3
2.2
2.1
2.0
1.1
1.0
0.7.3
0.6.9
0.6.8
0.6.10
0.5.9
0.5.8
0.5.7
0.5.11
0.5.10
0.4.9
0.4.8
0.4.7
0.4.11
0.4.10
0.3.9
0.3.7
0.3.11
0.3.10
0.2.8
0.2.6
0.2.5
0.2.4
Vendor: Canonical
Product: Ubuntu linux 
Version:
17.04
16.04
14.04
Vendor: Freebsd
Product: Freebsd 
Version:
11.1
11
10.4
10

CVSS2 => (AV:A/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.9/10
2.9/10
5.5/10
Exploit range
Attack complexity
Authentication
Adjacent network
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None

 References:
http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00020.html
http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00023.html
http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00024.html
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-007.txt
http://www.debian.org/security/2017/dsa-3999
http://www.kb.cert.org/vuls/id/228519
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
http://www.securityfocus.com/bid/101274
http://www.securitytracker.com/id/1039573
http://www.securitytracker.com/id/1039576
http://www.securitytracker.com/id/1039577
http://www.securitytracker.com/id/1039578
http://www.securitytracker.com/id/1039581
http://www.ubuntu.com/usn/USN-3455-1
https://access.redhat.com/errata/RHSA-2017:2907
https://access.redhat.com/security/vulnerabilities/kracks
https://cert-portal.siemens.com/productcert/pdf/ssa-901333.pdf
https://cert.vde.com/en-us/advisories/vde-2017-005
https://security.FreeBSD.org/advisories/FreeBSD-SA-17:07.wpa.asc
https://security.gentoo.org/glsa/201711-03
https://source.android.com/security/bulletin/2017-11-01
https://support.lenovo.com/us/en/product_security/LEN-17420
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171016-wpa
https://w1.fi/security/2017-1/wpa-packet-number-reuse-with-replayed-messages.txt
https://www.krackattacks.com/

Related CVE
CVE-2019-8936
NTP through 4.2.8p12 has a NULL Pointer Dereference.
CVE-2019-5598
In FreeBSD 11.3-PRERELEASE before r345378, 12.0-STABLE before r345377, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in pf does not check if the outer ICMP or ICMP6 packet has the same destination IP as the sour...
CVE-2019-5597
In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in the pf IPv6 fragment reassembly logic incorrectly uses the last extension header offset from the last r...
CVE-2019-5596
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX domain sockets can cause a file structure to be incorrectly released po...
CVE-2019-5595
In FreeBSD before 11.2-STABLE(r343782), 11.2-RELEASE-p9, 12.0-STABLE(r343781), and 12.0-RELEASE-p3, kernel callee-save registers are not properly sanitized before return from system calls, potentially allowing some kernel data used in the system call...
CVE-2018-17161
In FreeBSD before 11.2-STABLE(r348229), 11.2-RELEASE-p7, 12.0-STABLE(r342228), and 12.0-RELEASE-p1, insufficient validation of network-provided data in bootpd may make it possible for a malicious attacker to craft a bootp packet which could cause a s...
CVE-2018-17160
In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models provided by bhyve can permit a guest operating system to overwrite memory in the bhyve host possibly permitting arbitrary code execut...
CVE-2018-17159
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks a bounds check in the READDIRPLUS NFS request. Unprivileged remote users with access to the NFS server can cause a resource exhaustion by forcing the server to allocate ...

Copyright 2019, cxsecurity.com

 

Back to Top