Wi-Fi Protected Access Vulnerability in IEEE 802.11w by Various Vendors
CVE-2017-13081

5.3MEDIUM

Key Information:

Vendor
CVE Published:
17 October 2017

What is CVE-2017-13081?

This vulnerability in Wi-Fi Protected Access (WPA and WPA2) allows an attacker located within radio range to manipulate the group key handshake process, leading to the potential reinstallation of the Integrity Group Temporal Key (IGTK). By doing so, the attacker can spoof frames from access points to clients, enabling unauthorized data interception and manipulation. The flaw is present in devices that support the IEEE 802.11w standard, impacting the integrity and confidentiality of wireless communications.

Affected Version(s)

Wi-Fi Protected Access (WPA and WPA2) WPA

Wi-Fi Protected Access (WPA and WPA2) WPA2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.