ZeroHour

CVE-2017-13087

CVSS 3.0
5.3 medium
EPSS
2%p76
Published
()
Modified
Description

Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.

Vendors
canonicaldebianfreebsdopensuseredhatw1.fisuse
Products
ubuntu linux, debian linux, freebsd, leap, enterprise linux desktop, enterprise linux server, hostapd, wpa supplicant, linux enterprise desktop, linux enterprise point of sale, linux enterprise server, openstack cloud
Weakness
CWE-330
Vector
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news