CVE-2017-13079 is a medium-severity vulnerability affecting Wi-Fi Protected Access (WPA and WPA2) implementations that support IEEE 802.11w, impacting various operating systems and vendors including Canonical, Debian, and Red Hat. This flaw allows an attacker within radio range to spoof frames from access points to clients by reinstalling the Integrity Group Temporal Key (IGTK) during the four-way handshake. While the attack complexity is high and user interaction is not required, successful exploitation could lead to high integrity impacts, though confidentiality and availability are not affected. There is no evidence of active exploitation, and no public exploit code is available in Metasploit or ExploitDB, despite significant community discussion and media coverage as part of the broader "KRACK Attack" disclosures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.