CVE-2017-13082 is a high-severity vulnerability affecting Wi-Fi Protected Access (WPA/WPA2) implementations that support IEEE 802.11r, specifically impacting products from vendors like Canonical, Debian, and Red Hat. This flaw allows an attacker within radio range to reinstall the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission handshake. The attack vector is adjacent network, low complexity, and requires no user interaction, enabling attackers to replay, decrypt, or spoof frames, leading to high confidentiality and integrity impacts. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), the vulnerability garnered significant media attention and community discussion at the time of its disclosure, indicating widespread awareness. It is not currently listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.