ALPINE-CVE-2017-13082 PUBLISHED CVSS 8.100000381469727 HIGH

Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.

Risk Scores

CVSS v3.0
8.100000381469727
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Alpine:v3.10hostapd2.2-r0, 2.1-r0, 2.0-r1
Alpine:v3.23hostapd0.6.9-r0, 0.6.9-r1, 0.7.3-r0
Alpine:v3.12hostapd0, 0.6.10-r0, 0.6.10-r1
Alpine:v3.15hostapd2.3-r0, 2.2-r0, 2.1-r0
Alpine:v3.12wpa_supplicant2.0-r2, 2.6-r6, 2.6-r5
Alpine:v3.17hostapd2.6-r1, 2.6-r0, 2.5-r3
Alpine:v3.19hostapd0.6.10-r0, 0, 2.6-r1
Alpine:v3.7hostapd0.6.9-r0, 0.6.10-r2, 0.6.10-r1
Alpine:v3.15wpa_supplicant0, 2.6-r6, 2.6-r5
Alpine:v3.11wpa_supplicant2.4-r5, 0, 0.5.11-r0
Alpine:v3.5hostapd1.0-r0, 2.6-r0, 2.5-r3
Alpine:v3.16hostapd2.4-r0, 2.3-r0, 2.2-r0
Alpine:v3.16wpa_supplicant2.6-r5, 0, 0.5.11-r0
Alpine:v3.18wpa_supplicant2.6-r5, 2.1-r0, 2.1-r1
Alpine:v3.23wpa_supplicant2.0-r0, 2.3-r0, 2.3-r1
Alpine:v3.17wpa_supplicant2.1-r1, 2.0-r3, 2.0-r2
Alpine:v3.21hostapd0.6.10-r1, 0.6.10-r0, 0
Alpine:v3.19wpa_supplicant2.1-r0, 0.7.1-r1, 0.7.1-r0
Alpine:v3.18hostapd1.0-r2, 1.1-r0, 2.0-r0
Alpine:v3.14wpa_supplicant2.6-r1, 0, 0.5.11-r0

…and 18 more

Timeline

References

Open in Interactive Console →