CVE-2017-13078 is a medium-severity vulnerability affecting Wi-Fi Protected Access (WPA and WPA2) implementations across various operating systems and vendors, including Canonical, Debian, and Red Hat. It allows an attacker within radio range to replay frames from access points to clients by re-installing the Group Temporal Key (GTK) during the four-way handshake. This attack has high integrity impact, but no confidentiality or availability impact. The vulnerability has a CVSS score of 5.3 and an attack vector of Adjacent Network, with high attack complexity. While there is no evidence of active exploitation in the wild (not in KEV), and no public exploit code available (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, indicating widespread awareness. The FAUCET Risk Score is low at 21/100.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.