Key management errors - CVE-2017-13084

 

Key management errors - CVE-2017-13084

Published: October 17, 2017 / Updated: October 17, 2017


Vulnerability identifier: #VU8844
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13084
CWE-ID: CWE-320
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to force an STSL to reinstall a previously used STK.

The weakness exists in the processing of the 802.11i 4-way PeerKey handshake messages of the WPA and WPA2 protocols due to ambiguities in the processing of associated protocol messages. An adjacent attacker can use man-in-the-middle techniques to retransmit previously used messages exchanges between stations.

Affected software

Gentoo Linux
ArubaOS (AOS)
Junos OS
Slackware Linux
Cisco WAP371
Cisco WAP321
Cisco WAP121
Cisco ASA 5506W-X w
Cisco Spark Room Series
Cisco IP Phone 8865
Cisco IP Phone 8861
Cisco DX80 Series IP Phones
Cisco DX70 Series IP Phones
Cisco WAP551
Cisco WAP561
Stratix 5100
Cisco Meraki
Cisco Wireless IP Phone 8821
Aironet

How to mitigate CVE-2017-13084



External References

Related Security Bulletins