CVE-2017-13087 is a medium-severity vulnerability affecting Wi-Fi Protected Access (WPA/WPA2) implementations supporting 802.11v, found in products from vendors like Canonical, Debian, and Red Hat. It allows an attacker within radio range to replay frames from access points to clients by reinstalling the Group Temporal Key (GTK) via a Wireless Network Management (WNM) Sleep Mode Response frame. The attack has high impact on integrity but no impact on confidentiality or availability, with a CVSS score of 5.3. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered significant community discussion and media coverage, indicating awareness despite no confirmed active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.