CVE-2017-13078 (NVD)

2017-10-17

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.

Products Ubuntu_linux, Debian_linux, Freebsd, Leap, Enterprise_linux_desktop, Enterprise_linux_server, Linux_enterprise_desktop, Linux_enterprise_point_of_sale, Linux_enterprise_server, Openstack_cloud, Hostapd, Wpa_supplicant
Type Use of Insufficiently Random Values (CWE-330)
First patch - None (likely due to unavailable code)
Links http://www.kb.cert.org/vuls/id/228519
https://security.FreeBSD.org/advisories/FreeBSD-SA-17:07.wpa.asc
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171016-wpa
http://www.securitytracker.com/id/1039578
http://www.securitytracker.com/id/1039573