WPA2 Key Reinstallation Multiple Security Weaknesses
BID:101274
Info
WPA2 Key Reinstallation Multiple Security Weaknesses
| Bugtraq ID: | 101274 |
| Class: | Design Error |
| CVE: |
CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080 CVE-2017-13081 CVE-2017-13082 CVE-2017-13084 CVE-2017-13086 CVE-2017-13087 CVE-2017-13088 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2017 12:00AM |
| Updated: | Feb 21 2019 09:00AM |
| Credit: | Mathy Vanhoef from imec-DistriNet and KU Leuven. |
| Vulnerable: |
Wi-Fi Alliance WPA2 (Wi-Fi Protected Access 2) 0 W1.F1 wpa_supplicant 2.6 W1.F1 wpa_supplicant 2.4 Ubiquiti Networks UniFi Access Point 0 Toshiba SureMark 4610 Printer 2NR Toshiba SureMark 4610 Printer 2CR Toshiba SureMark 4610 Printer 1NR Stryker Secure II Med-Surg Bed 3002 Stryker S3 Med-Surg Bed 3005 Stryker S3 Med-Surg Bed 3002 Stryker InTouch Critical Care Bed 2141 Stryker InTouch Critical Care Bed 2131 Siemens SINAMICS V20 Smart Access Module 0 Siemens SIMATIC Mobile Panel 277(F) IWLAN 0 Siemens SIMATIC IWLAN-PB/LINK 0 Siemens SIMATIC ET200 PRO IM154-6 PN IWLAN 0 Siemens SCALANCE WLC712 0 Siemens SCALANCE WLC711 0 Siemens SCALANCE W1750D 0 Siemens SCALANCE W-700 (IEEE 802.11n) 0 Siemens SCALANCE W-700 (IEEE 802.11a/b/g) 0 Siemens RUGGEDCOM RX1400 0 Siemens RUGGEDCOM RS9xxW 0 Rockwell Automation Stratix 5100 15.3(3)JC1 Redhat Enterprise Linux Workstation 7 Redhat Enterprise Linux Server - Update Services for SAP Solutions 7.6 Redhat Enterprise Linux Server - Update Services for SAP Solutions 7.4 Redhat Enterprise Linux Server - TUS 7.6 Redhat Enterprise Linux Server - TUS 7.4 Redhat Enterprise Linux Server - Extended Update Support 7.6 Redhat Enterprise Linux Server - Extended Update Support 7.5 Redhat Enterprise Linux Server - Extended Update Support 7.4 Redhat Enterprise Linux Server - AUS 7.6 Redhat Enterprise Linux Server - AUS 7.4 Redhat Enterprise Linux Server (for IBM Power LE) - Update Services for SAP Solutions 7. Redhat Enterprise Linux Server (for IBM Power LE) - Update Services for SAP Solutions 7. Redhat Enterprise Linux Server 7 Redhat Enterprise Linux for Scientific Computing 7 Redhat Enterprise Linux for Power, little endian - Extended Update Supp 7.6 Redhat Enterprise Linux for Power, little endian - Extended Update Supp 7.5 Redhat Enterprise Linux for Power, little endian - Extended Update Supp 7.4 Redhat Enterprise Linux for Power, little endian 7 Redhat Enterprise Linux for Power, big endian - Extended Update Support 7.6 Redhat Enterprise Linux for Power, big endian - Extended Update Support 7.5 Redhat Enterprise Linux for Power, big endian - Extended Update Support 7.4 Redhat Enterprise Linux for Power, big endian 7 Redhat Enterprise Linux for IBM z Systems - Extended Update Support 7.6 Redhat Enterprise Linux for IBM z Systems - Extended Update Support 7.5 Redhat Enterprise Linux for IBM z Systems - Extended Update Support 7.4 Redhat Enterprise Linux for IBM z Systems 7 Redhat Enterprise Linux EUS Compute Node 7.6 Redhat Enterprise Linux EUS Compute Node 7.5 Redhat Enterprise Linux EUS Compute Node 7.4 Redhat Enterprise Linux Desktop 7 Phoenix Contact VMT 70xx 0 Phoenix Contact VMT 50xx 0 Phoenix Contact VMT 30xx 0 Phoenix Contact TPC 6013 0 Phoenix Contact RAD-WHG/WLAN-XD 0 Phoenix Contact RAD-80211-XD 0 Phoenix Contact ITC 8113 0 Phoenix Contact FL WLAN SPA 0 Phoenix Contact FL WLAN EPA 0 Phoenix Contact FL WLAN 510x 0 Phoenix Contact FL WLAN 24 EC 802-11 0 Phoenix Contact FL WLAN 24 DAP 802-11 0 Phoenix Contact FL WLAN 24 AP 802-11 0 Phoenix Contact FL WLAN 230 AP 802-11 0 Phoenix Contact FL WLAN 210x 0 Phoenix Contact FL WLAN 110x 0 Phoenix Contact FL COMSERVER WLAN 232/422/485 0 Phoenix Contact BL2 PPC 0 Phoenix Contact BL2 BPC 0 Pepperl+Fuchs Tab-Ex 01 0 Pepperl+Fuchs Smart-Ex 201 0 Pepperl+Fuchs Smart-Ex 01 0 Pepperl+Fuchs Pad-Ex 01 0 Pepperl+Fuchs i.roc Ci70-Ex 0 Pepperl+Fuchs Ex-Handy 209 0 Pepperl+Fuchs Ex-Handy 09 0 Pepperl+Fuchs CN70E-ATEX 0 Pepperl+Fuchs CN70A-ATEX 0 Pepperl+Fuchs CK71A-ATEX 0 Pepperl+Fuchs CK70A-ATEX 0 Oracle MICROS Handheld Terminal 0 Microsoft Windows Server 2012 R2 0 Microsoft Windows Server 2012 0 Microsoft Windows Server 2008 R2 for Itanium-based Systems SP1 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2016 Microsoft Windows RT 8.1 Microsoft Windows 8.1 for x64-based Systems 0 Microsoft Windows 8.1 for 32-bit Systems 0 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Windows 10 version 1703 for x64-based Systems 0 Microsoft Windows 10 version 1703 for 32-bit Systems 0 Microsoft Windows 10 Version 1607 for x64-based Systems 0 Microsoft Windows 10 Version 1607 for 32-bit Systems 0 Microsoft Windows 10 version 1511 for x64-based Systems 0 Microsoft Windows 10 version 1511 for 32-bit Systems 0 Microsoft Windows 10 for x64-based Systems 0 Microsoft Windows 10 for 32-bit Systems 0 Intel Dual Band Wireless-AC 8265 20.0.2.2 Intel Dual Band Wireless-AC 8265 20.0.0.0 Intel Dual Band Wireless-AC 8260 20.0.2.2 Intel Dual Band Wireless-AC 8260 20.0.0.0 Intel Dual Band Wireless-AC 7265 19.10 Intel Dual Band Wireless-AC 7265 19.51.7.1 Intel Dual Band Wireless-AC 7265 19.51.0.0 Intel Dual Band Wireless-AC 7265 19.10.9.1 Intel Dual Band Wireless-AC 7260 18.33.9.2 Intel Dual Band Wireless-AC 7260 18.0.0.0 Intel Dual Band Wireless-AC 3168 19.10 Intel Dual Band Wireless-AC 3168 19.51.7.1 Intel Dual Band Wireless-AC 3168 19.51.0.0 Intel Dual Band Wireless-AC 3168 19.10.9.1 Intel Dual Band Wireless-AC 3165 19.10 Intel Dual Band Wireless-AC 3165 19.51.7.1 Intel Dual Band Wireless-AC 3165 19.51.0.0 Intel Dual Band Wireless-AC 3165 19.10.9.1 Intel Dual Band Wireless-AC 3160 18.33.9.2 Intel Dual Band Wireless-AC 3160 18.0.0.0 Intel Atom Processor C3200 Series for Yocto Project BSP MR4 Intel Active Management Technology 9.5 Intel Active Management Technology 9.1.41.3024 Intel Active Management Technology 9.1.40.100 Intel Active Management Technology 9.1 Intel Active Management Technology 9.0 Intel Active Management Technology 8.1.71.3608 Intel Active Management Technology 8.1 Intel Active Management Technology 8.0 Intel Active Management Technology 7.1.91.3272 Intel Active Management Technology 7.1 Intel Active Management Technology 7.0 Intel Active Management Technology 6.2.61.3535 Intel Active Management Technology 6.2 Intel Active Management Technology 6.1 Intel Active Management Technology 6.0 Intel Active Management Technology 4.0 Intel Active Management Technology 2.6 Intel Active Management Technology 2.5 Intel Active Management Technology 11.8 Intel Active Management Technology 11.6.27.3264 Intel Active Management Technology 11.6.0.1000 Intel Active Management Technology 11.6 Intel Active Management Technology 11.5 Intel Active Management Technology 11.0.26.3000 Intel Active Management Technology 11.0.25.3001 Intel Active Management Technology 11.0.0.1205 Intel Active Management Technology 11.0 Intel Active Management Technology 10.0.55.3000 Intel Active Management Technology 10.0.0.50.1004 Intel Active Management Technology 10.0 Google Android 7.1.1 Google Android 6.0.1 Google Android 8.0 Google Android 7.1.2 Google Android 7.1.0 Google Android 7.0 Google Android 6.1 Google Android 6.0 Espressif Systems ESP8266 0 Espressif Systems ESP32 0 Cisco Wireless IP Phone 8821 0 Cisco WAP561 Wireless-N Dual Radio Selectable Band Access Point 0 Cisco WAP551 Wireless-N Single Radio Selectable Band Access Point 0 Cisco WAP371 Wireless-AC N Access Point with Single Point Setup 0 Cisco WAP321 Wireless-N Access Point with Single Point Setup 0 Cisco WAP121 Wireless-N Access Point with Single Point Setup 0 Cisco TelePresence Collaboration Endpoint 0 Cisco Meraki MR84 0 Cisco Meraki MR74 0 Cisco Meraki MR72 0 Cisco Meraki MR66 0 Cisco Meraki MR62 0 Cisco Meraki MR58 0 Cisco Meraki MR53 0 Cisco Meraki MR52 0 Cisco Meraki MR42 0 Cisco Meraki MR34 0 Cisco Meraki MR33 0 Cisco Meraki MR32 0 Cisco Meraki MR30H 0 Cisco Meraki MR26 0 Cisco Meraki MR24 0 Cisco Meraki MR18 0 Cisco Meraki MR16 0 Cisco Meraki MR14 0 Cisco Meraki MR12 0 Cisco Meraki MR11 0 Cisco IP Phone 8865 0 Cisco IP Phone 8861 0 Cisco DX80 0 Cisco DX70 0 Cisco ASA 5506W-X w/ FirePOWER Services 0 Cisco AnyConnect Secure Mobility Client 0 Cisco Aironet Access Points 0 Cisco Aironet 3800 Series Access Points 0 Cisco Aironet 2800 Series Access Points 0 Cisco Aironet 1850 Series Access Points 0 Cisco Aironet 1830 Series Access Points 0 Cisco Aironet 1815 Series Access Points 0 Cisco Aironet 1810w Series Access Points 0 Cisco Aironet 1810 Series OfficeExtend Access Points 0 Cisco Aironet 1560 Series Access Points 0 BD Pyxis SupplyStation 0 BD Pyxis Supply Roller 0 BD Pyxis StockStation System 0 BD Pyxis Parx handheld 0 BD Pyxis Parx 0 BD Pyxis ParAssist System 0 BD Pyxis MedStation ES 0 BD Pyxis MedStation 4000 T2 0 BD Pyxis CIISafe �?? Workstation 0 BD Pyxis Anesthesia System 4000 0 BD Pyxis Anesthesia System 3500 0 BD Pyxis Anesthesia ES 0 Arubanetworks InstantOS 6.5.4 Arubanetworks InstantOS 6.5.3 Arubanetworks InstantOS 6.5.2 Arubanetworks InstantOS 4.2 Arubanetworks InstantOS 6.5.4.1 Arubanetworks InstantOS 6.5.3.2 Arubanetworks InstantOS 4.3.1.5 Arubanetworks InstantOS 4.3 Arubanetworks InstantOS 4.2.4.8 Arubanetworks Clarity Engine 1.0 Arubanetworks Arubaos 6.5.4 Arubanetworks Arubaos 6.5.3 Arubanetworks Arubaos 6.5.1 Arubanetworks ArubaOS 6.4 Arubanetworks Arubaos 8.1.0.3 Arubanetworks Arubaos 6.5.4.1 Arubanetworks Arubaos 6.5.3.2 Arubanetworks Arubaos 6.5.2.0 Arubanetworks Arubaos 6.5.0.0 Arubanetworks Arubaos 6.4.4.15 Arubanetworks ArubaOS 6.4.2.4 Arubanetworks Arubaos 6.4.2.1 Arubanetworks ArubaOS 6.4.1.0 Arubanetworks ArubaOS 6.3.1.8 Arubanetworks ArubaOS 6.3.1.15 Arubanetworks AirMesh MSR 0 Arubanetworks 501 Wireless Client Bridge 0 Apple Wi-Fi Update for Boot Camp 0 Apple watchOS 4.1 Apple watchOS 4 Apple Watch 0 Apple tvOS 10.1.1 Apple tvOS 10.0.1 Apple tvOS 11.1 Apple tvOS 10.2.2 Apple tvOS 10.2.1 Apple tvOS 10.2 Apple tvOS 10.1 Apple TV 0 Apple MacMini 0 Apple Macbook Pro 0 Apple Macbook Air 0 Apple MacBook 0 Apple iPod Touch 0 Apple iPhone 0 Apple iPad Air 0 Apple iPad 0 Apple iOS 10.2.1 Apple iOS 10.0.1 Apple iOS 11.1 Apple iOS 10.3.3 Apple iOS 10.3.2 Apple iOS 10.3.1 Apple iOS 10.3 Apple iOS 10.2 Apple iOS 10.1 Apple IMac 0 Apple AirPort Time Capsule 0 Apple Airport Extreme 0 Apple Airport Express 0 Apple Airport Base Station Firmware 7.7.8 Apple Airport Base Station Firmware 7.7.7 Apple Airport Base Station Firmware 7.7.3 Apple Airport Base Station Firmware 7.6.8 Apple Airport Base Station Firmware 7.6.7 Apple Airport Base Station Firmware 7.6.4 Apple Airport Base Station Firmware 7.6.3 Apple Airport Base Station Firmware 7.6.2 Apple Airport Base Station Firmware 7.6.1 Apple Airport Base Station Firmware 7.6 ABB TropOS broadband mesh routers and bridges 0 |
| Not Vulnerable: |
Oracle MICROS Handheld Terminal 2.03.0.0.021R Intel Dual Band Wireless-AC 8265 20.0.2.3 Intel Dual Band Wireless-AC 8260 20.0.2.3 Intel Dual Band Wireless-AC 7265 19.51.7.20 Intel Dual Band Wireless-AC 7265 19.10.9.2 Intel Dual Band Wireless-AC 7260 18.33.9.3 Intel Dual Band Wireless-AC 3168 19.51.7.20 Intel Dual Band Wireless-AC 3168 19.10.9.2 Intel Dual Band Wireless-AC 3165 19.51.7.20 Intel Dual Band Wireless-AC 3165 19.10.9.2 Intel Dual Band Wireless-AC 3160 18.33.9.3 Intel Atom Processor C3200 Series for Yocto Project BSP MR4.1 Arubanetworks InstantOS 6.5.4.2 Arubanetworks InstantOS 6.5.3.3 Arubanetworks InstantOS 4.3.1.6 Arubanetworks InstantOS 4.2.4.9 Arubanetworks Clarity Engine 1.0.0.1 Arubanetworks Arubaos 8.1.0.4 Arubanetworks Arubaos 6.5.4.2 Arubanetworks Arubaos 6.5.3.3 Arubanetworks Arubaos 6.5.1.9 Arubanetworks Arubaos 6.4.4.16 Arubanetworks Arubaos 6.3.1.25 Arubanetworks 501 Wireless Client Bridge 2.0.0.1-Aruba501-B00 Arubanetworks 501 Wireless Client Bridge 1.0.1.3-HP501-B0012 Apple Wi-Fi Update for Boot Camp 6.4.0 Apple watchOS 4.2 Apple tvOS 11.2 Apple iOS 11.2 Apple Airport Base Station Firmware 7.7.9 Apple Airport Base Station Firmware 7.6.9 |
Discussion
WPA2 Key Reinstallation Multiple Security Weaknesses
WPA2 is prone to multiple security weaknesses.
Exploiting these issues may allow an unauthorized user to intercept and manipulate data or disclose sensitive information. This may aid in further attacks.
WPA2 is prone to multiple security weaknesses.
Exploiting these issues may allow an unauthorized user to intercept and manipulate data or disclose sensitive information. This may aid in further attacks.
Exploit / POC
WPA2 Key Reinstallation Multiple Security Weaknesses
The researcher created proof-of-concepts to demonstrate these issues. Please see the references for more information.
The researcher created proof-of-concepts to demonstrate these issues. Please see the references for more information.
Solution / Fix
WPA2 Key Reinstallation Multiple Security Weaknesses
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
WPA2 Key Reinstallation Multiple Security Weaknesses
References:
References:
- stevenhoneyman/wpa_gui (stevenhoneyman)
- Wi-Fi Alliance Home Page (Wi-Fi Alliance)
- Wi-Fi Update for Boot Camp 6.4.0 (Apple)
- About the security content of iOS 11.2 (Apple)
- About the security content of tvOS 11.2 (Apple)
- About the security content of watchOS 4.2 (Apple)
- Advisory (ICSA-17-353-02) PEPPERL+FUCHS/ecom instruments WLAN Capable Devices us (ICS CERT)
- Advisory (ICSMA-18-114-01) BD Pyxis (CERT)
- APPLE-SA-2017-12-13-6 Additional information for APPLE-SA-2017-12-6-2 iOS 11.2 (Apple)
- APPLE-SA-2017-12-13-7 Additional information for APPLE-SA-2017-12-6-4 tvOS 11.2 (Apple)
- APPLE-SA-2018-7-05-1 Wi-Fi Update for Boot Camp 6.4.0 (Apple)
- Aruba Product Security Advisory ARUBA-PSA-2017-007 (Aruba)
- cisco-sa-20171016-wpa: Multiple Vulnerabilities in Wi-Fi Protected Access and Wi (Cisco)
- CVE-2017-13077 (Red Hat)
- CVE-2017-13078 (Red Hat)
- CVE-2017-13079 (Red Hat)
- CVE-2017-13080 (Red Hat)
- CVE-2017-13080 | Windows Wireless WPA Group Key Reinstallation Vulnerability (Microsoft)
- CVE-2017-13081 (Red Hat)
- CVE-2017-13082 (Red Hat)
- CVE-2017-13084 (Red Hat)
- CVE-2017-13086 (Red Hat)
- CVE-2017-13087 (Red Hat)
- CVE-2017-13088 (Red Hat)
- FortiAP 5.6.1 (Fortinet)
- ICSA-17-299-02:Rockwell Automation Stratix 5100 (CERT)
- ICSA-17-318-01:Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (CERT)
- ICSA-17-318-02: ABB TropOS (CERT)
- ICSA-17-325-01: PHOENIX CONTACT WLAN Capable Devices using the WPA2 Protocol (ICS CERT)
- Index of /security/2017-1 (W1.f1)
- INTEL-SA-00101 One or more Intel Products affected by the WPA2 protocol vulnerab (INtel)
- Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse (Mathy Vanhoe)
- Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2 (mathyvanhoef)
- Medical Advisory (ICSMA-19-029-01) (ICS-CERT)
- Oracle Critical Patch Update Advisory - April 2018 (Oracle)
- RHSA-2017:2907 - Security Advisory (Red Hat)
- RHSA-2017:2911 - Security Advisory (Red Hat)
- VU#228519 WPA2 handshake traffic can be manipulated to induce nonce and session (CERT)