CVE-2017-13079

Publication date 16 October 2017

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

5.3 · Medium

Score breakdown

Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients.

Status

Package Ubuntu Release Status
wpa 17.04 zesty
Fixed 2.4-0ubuntu9.1
16.04 LTS xenial
Fixed 2.4-0ubuntu6.2
14.04 LTS trusty
Fixed 2.1-0ubuntu1.5

Severity score breakdown

Parameter Value
Base score 5.3 · Medium
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact High
Availability impact None
Vector CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

References

Related Ubuntu Security Notices (USN)

    • USN-3455-1
    • wpa_supplicant and hostapd vulnerabilities
    • 16 October 2017

Other references