CVE-2017-13080 is a medium-severity vulnerability affecting Wi-Fi Protected Access (WPA and WPA2) in various operating systems and wireless drivers, including canonical, debian, and opensuse. It allows an attacker within radio range to replay frames from access points to clients due to improper reinstallation of the Group Temporal Key (GTK) during the group key handshake. The attack requires high attack complexity but can lead to high integrity impact, with no confidentiality or availability impact. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability garnered significant community discussion and media coverage at the time of its disclosure, indicating high awareness. It is not currently listed on CISA's KEV catalog and is considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.