Key management errors - CVE-2017-13086

 

Key management errors - CVE-2017-13086

Published: October 17, 2017 / Updated: October 17, 2017


Vulnerability identifier: #VU8845
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13086
CWE-ID: CWE-320
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to force a supplicant that is compliant with the 802.11z standard to reinstall a previously used TPK key.

The weakness exists in the processing of the 802.11z (Extensions to Direct-Link Setup) TDLS handshake messages due to ambiguities in the processing of associated protocol messages. An adjacent attacker can passively eavesdrop on a TDLS handshake and retransmit previously used message exchanges between supplicant and authenticator.

Affected software

Stratix 5100
Cisco WAP561
Cisco WAP551
Cisco WAP371
Cisco WAP321
Cisco WAP121
Cisco ASA 5506W-X w
Cisco Spark Room Series
Cisco IP Phone 8865
Cisco IP Phone 8861
Cisco DX80 Series IP Phones
Cisco DX70 Series IP Phones
Cisco Meraki
Cisco Wireless IP Phone 8821
Arch Linux
Debian Linux
Gentoo Linux
Fedora
ArubaOS (AOS)
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server (for IBM Power LE) - 4 Year Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - 4 Year Extended Update Support
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
FreeBSD
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Junos OS
Slackware Linux
Ubuntu
Aironet
busybox (Alpine package)
hostapd (Alpine package)
wpa_supplicant (Alpine package)
wpa_supplicant
supplicant (Red Hat package)
hostapd
wpa_supplicant-debugsource
wpa_supplicant-debuginfo

How to mitigate CVE-2017-13086


hostapd (Alpine package) - addressed in versions 2.6-r1, 2.6-r2
wpa_supplicant (Alpine package) - update to 2.6-r2
wpa_supplicant - addressed in versions 2.6-3.fc25.1, 2.6-11.fc26, 2.6-11.fc27
supplicant (Red Hat package) - update to 2.6-5.el7_4.1
hostapd - addressed in versions 2.6-6.fc25, 2.6-6.fc26, 2.6-6.fc27, 2.6-7.el6, 2.6-7.el7
wpa_supplicant-debugsource - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant - update to 2.9-15.22.1

External References

Related Security Bulletins