ENISA EUVD · EUVD-2017-4600Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2025-0369IEEE WPA2: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in IEEE WPA2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-012Oracle Critical Patch updates6-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-6814, CVE-2016-7052, CVE-2016-7055, CVE-2016-7977, CVE-2016-8735, CVE-2016-9878, CVE-2017-0781, CVE-2017-0782, CVE-2017-0783, CVE-2017-0785, CVE-2017-3730, CVE-2017-3731, CVE-2017-3732, CVE-2017-3733, CVE-2017-3735, CVE-2017-3736, CVE-2017-3737, CVE-2017-3738, CVE-2017-5461, CVE-2017-5645, CVE-2017-5664, CVE-2017-5715, CVE-2017-9072, CVE-2017-9798, CVE-2017-10068, CVE-2017-10262, CVE-2017-10273, CVE-2017-10282, CVE-2017-10301, CVE-2017-10352, CVE-2017-12617, CVE-2017-13077, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2018-2560, CVE-2018-2561, CVE-2018-2562, CVE-2018-2564, CVE-2018-2565, CVE-2018-2566, CVE-2018-2567, CVE-2018-2568, CVE-2018-2569, CVE-2018-2570, CVE-2018-2571, CVE-2018-2573, CVE-2018-2574, CVE-2018-2575, CVE-2018-2576, CVE-2018-2577, CVE-2018-2578, CVE-2018-2579, CVE-2018-2580, CVE-2018-2581, CVE-2018-2582, CVE-2018-2583, CVE-2018-2584, CVE-2018-2585, CVE-2018-2586, CVE-2018-2588, CVE-2018-2589, CVE-2018-2590, CVE-2018-2591, CVE-2018-2592, CVE-2018-2593, CVE-2018-2594, CVE-2018-2595, CVE-2018-2596, CVE-2018-2597, CVE-2018-2599, CVE-2018-2600, CVE-2018-2601, CVE-2018-2602, CVE-2018-2603, CVE-2018-2604, CVE-2018-2605, CVE-2018-2606, CVE
Official advisory ↗Canadian Centre for Cyber Security · English · AV17-172Cisco security updatesLL Preloading Vulnerability
Cisco HyperFlex System Authenticated Information Disclosure Vulnerability
Cisco Firepower System Software Server Message Block Version 2 File Policy Bypass Vulnerability
Cisco ASA Next-Generation Firewall Services Local Management Filtering Bypass Vulnerability
Cisco FindIT Discovery Utility Insecure Library Loading Vulnerability
Cisco Email Security Appliance HTTP Response Splitting Vulnerability
Cisco Network Academy Packet Tracer DLL Preload Vulnerability
Cisco Meeting Server H.264 Decoding Denial of Service Vulnerability
CVE References: CVE-2017-13077,CVE-2017-13078,CVE-2017-13079,CVE-2017-13080,CVE-2017-13081,CVE-2017-13082,CVE-2017-13084,CVE-2017-13086,CVE-2017-13087,CVE-2017-13088,CVE-2017-12303,CVE-2017-12337,CVE-2017-12350,CVE-2017-12302,CVE-2017-12306,CVE-2017-12318,CVE-2017-12290,CVE-2017-12290,CVE-2017-12291,CVE-2017-12292,CVE-2017-12320,CVE-2017-12321,CVE-2017-12322,CVE-2017-12323,CVE-2017-12316,CVE-2017-12305,CVE-2017-12304,CVE-2017-12312,CVE-2017-12315,CVE-2017-12300,CVE-2017-12299,CVE-2017-12314,CVE-2017-12309,CVE-2017-12313,CVE-2017-12311
Suggested Action
CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.
References:
https://tools.cisco.com/security/center/content/CiscoSecuri
Official advisory ↗Canadian Centre for Cyber Security · English · AL17-012Wi-Fi Protected Access II (WPA2) Handshake VulnerabilitiesCCIRC has become aware of multiple critical vulnerabilities in WPA2 handshake traffic. These vulnerabilities can be manipulated to induce nonce and session key reuse which could result in key reinstallation by a wireless access point or client. This could then enable arbitrary packet decryption and injection, TCP connection hijacking, HTTP content injection, or the replay of unicast, broadcast, and multicast frames.
As these vulnerabilities are in the Wi-Fi standard, they are not related to individual products or their implementation. However, the correct implementation of the WPA2 protocol is likely affected.
The WPA2 protocol is affected by the following vulnerabilities:
CVE-2017-13077: Reinstallation of the pairwise encryption key (PTK-TK) in the 4-way handshake.
CVE-2017-13078: Reinstallation of the group key (GTK) in the 4-way handshake.
CVE-2017-13079: Reinstallation of the integrity group key (IGTK) in the 4-way handshake.
CVE-2017-13080: Reinstallation of the group key (GTK) in the group key handshake.
CVE-2017-13081: Reinstallation of the integrity group key (IGTK) in the group key handshake.
CVE-2017-13082: Accepting a retransmitted Fast BSS Transition (FT) Reassociation Request and reinstalling the pairwise encryption key (PTK-TK) while processing it.
CVE-2017-13084: Reinstallation of the STK key in the PeerKey handshake.
CVE-2017-13086: Reinstallation of the Tunneled Direct-Link Setup (TDLS) PeerKey (TPK) key in the TDLS handshake.
CVE-2017-13087: Reinstallation of the group key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame.
CVE-2017-13088: Reinstallation of the integrity group key (IGTK) when processing a Wireless Network management (WNM) Sleep Mode Response frame
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-267Multiples vulnérabilités dans Juniper Networks Junos Spaceid=CVE-2017-1000158
Référence CVE CVE-2017-10664
https://www.cve.org/CVERecord?id=CVE-2017-10664
Référence CVE CVE-2017-10784
https://www.cve.org/CVERecord?id=CVE-2017-10784
Référence CVE CVE-2017-11368
https://www.cve.org/CVERecord?id=CVE-2017-11368
Référence CVE CVE-2017-11671
https://www.cve.org/CVERecord?id=CVE-2017-11671
Référence CVE CVE-2017-12652
https://www.cve.org/CVERecord?id=CVE-2017-12652
Référence CVE CVE-2017-13077
https://www.cve.org/CVERecord?id=CVE-2017-13077
Référence CVE CVE-2017-13078
https://www.cve.org/CVERecord?id=CVE-2017-13078
Référence CVE CVE-2017-13080
https://www.cve.org/CVERecord?id=CVE-2017-13080
Référence CVE CVE-2017-13082
https://www.cve.org/CVERecord?id=CVE-2017-13082
Référence CVE CVE-2017-13086
https://www.cve.org/CVERecord?id=CVE-2017-13086
Référence CVE CVE-2017-13087
https://www.cve.org/CVERecord?id=CVE-2017-13087
Référence CVE CVE-2017-13088
https://www.cve.org/CVERecord?id=CVE-2017-13088
Référence CVE CVE-2017-13089
https://www.cve.org/CVERecord?id=CVE-2017-13089
Référence CVE CVE-2017-13090
https://www.cve.org/CVERecord?id=CVE-2017-13090
Référence CVE CVE-2017-13672
https://www.cve.org/CVERecord?id=CVE-2017-13672
Référence CVE CVE-2017-13711
https://www.cve.org/CVERecord?id=CVE-2017-13711
Référence CVE CVE-2017-13720
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2017-AVI-398Multiples vulnérabilités dans NVIDIA Shield TabletDe multiples vulnérabilités ont été découvertes dans NVIDIA Shield
Tablet. Certaines d'entre elles permettent à un attaquant de provoquer
un déni de service, une atteinte à l'intégrité des données et une
atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2017-AVI-394Multiples vulnérabilités dans Google Android (Nexus)d?id=CVE-2017-11015
Référence CVE CVE-2017-11017
https://www.cve.org/CVERecord?id=CVE-2017-11017
Référence CVE CVE-2017-11028
https://www.cve.org/CVERecord?id=CVE-2017-11028
Référence CVE CVE-2017-11092
https://www.cve.org/CVERecord?id=CVE-2017-11092
Référence CVE CVE-2017-13077
https://www.cve.org/CVERecord?id=CVE-2017-13077
Référence CVE CVE-2017-13078
https://www.cve.org/CVERecord?id=CVE-2017-13078
Référence CVE CVE-2017-13079
https://www.cve.org/CVERecord?id=CVE-2017-13079
Référence CVE CVE-2017-13080
https://www.cve.org/CVERecord?id=CVE-2017-13080
Référence CVE CVE-2017-13081
https://www.cve.org/CVERecord?id=CVE-2017-13081
Référence CVE CVE-2017-13082
https://www.cve.org/CVERecord?id=CVE-2017-13082
Référence CVE CVE-2017-13086
https://www.cve.org/CVERecord?id=CVE-2017-13086
Référence CVE CVE-2017-13087
https://www.cve.org/CVERecord?id=CVE-2017-13087
Référence CVE CVE-2017-13088
https://www.cve.org/CVERecord?id=CVE-2017-13088
Référence CVE CVE-2017-6264
https://www.cve.org/CVERecord?id=CVE-2017-6264
Référence CVE CVE-2017-7541
https://www.cve.org/CVERecord?id=CVE-2017-7541
Référence CVE CVE-2017-9077
https://www.cve.org/CVERecord?id=CVE-2017-9077
Référence CVE CVE-2017-9690
https://www.cve.org/CVERecord?id=CVE-2017-9690
Gestion détaillée du document
le 07 novembre 2017
Version initiale
le
Official advisory ↗CERT-FR · French · CERTFR-2017-AVI-361Multiples vulnérabilités dans les produits Juniper utilisant le protocole WPA/WPA2De multiples vulnérabilités ont été découvertes dans les produits
Juniper utilisant le protocole WPA/WPA2 . Elles permettent à un
attaquant de provoquer une atteinte à l'intégrité des données et une
atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2017-AVI-359Multiples vulnérabilités dans Ubuntu wpa_supplicant et hostpadDe multiples vulnérabilités ont été découvertes dans Ubuntu
wpa_supplicant et hostpad. Certaines d'entre elles permettent à un
attaquant de provoquer une exécution de code arbitraire, un déni de
service à distance et un déni de service.
Official advisory ↗CERT-FR · French · CERTFR-2017-AVI-360Multiples vulnérabilités dans les produits Fortinet utilisant le protocole WPA/WPA2De multiples vulnérabilités ont été découvertes dans les produits
Fortinet utilisant le protocole WPA/WPA2. Elles permettent à un
attaquant de provoquer une atteinte à l'intégrité des données et une
atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2017-AVI-358Multiples vulnérabilités dans Debian sur le protocole WPA/WPA2De multiples vulnérabilités ont été découvertes dans Debian sur le
protocole WPA/WPA2. Elles permettent à un attaquant de provoquer une
atteinte à l'intégrité des données et une atteinte à la confidentialité
des données.
Official advisory ↗JVN iPedia · Japanese · JVNDB-2017-009175Wi-Fi Protected Access における Pairwise Transient Key Temporal Key を再インストールされる脆弱性Wi-Fi Protected Access (WPA および WPA2) には、4-way ハンドシェイク中に、Pairwise Transient Key (PTK) Temporal Key (TK) を再インストールされ、フレームを再生、復号、または偽装される脆弱性が存在します。
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-4807Cisco 제품군 취약점 보안 업데이트 권고CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082)[2]
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-4802Cisco 제품군 취약점 보안 업데이트 권고CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2017-13084,
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-4803KRACK Wi-Fi 암호기술(WPA2) 취약점 보안 업데이트 권고7.10.17
##### □ 개요
o Wi-Fi 암호 기술인 WPA2를 사용하는 운영체제에서 악용 가능한 취약점(KRACK, Key Reinstallation Attacks)이 공개됨[1]
o 영향 받는 버전의 사용자는 개인정보 유출 및 통신 도청 등에 피해를 입을 수 있기 때문에 해결방안에 따라 최신 버전으로 업데이트 권고
##### □ 취약점 설명
o 4-way-handshake에서 양방향 암호화키(PTK-TK)를 재설치하여 정보 유출이 가능한 취약점(CVE-2017-13077)
o 4-way-handshake에서 그룹 암호화키(GTK)를 재설치하여 정보 유출이 가능한 취약점(CVE-2017-13078)
o 4-way-handshake에서 무결성 그룹 암호화키(IGTK)를 재설치하여 정보 유출이 가능한 취약점(CVE-2017-13079)
o 그룹 Key handshake에서 그룹 암호화키(GTK)를 재설치하여 정보 유출이 가능한 취약점(CVE-2017-13080)
o 그룹 Key handshake에서 무결성 그룹 암호화키(IGTK)를 재설치하여 정보 유출이 가능한 취약점(CVE-2017-13081)
o 재전송된 FT(Fast BSS Translation)를 연결 하는 동안 양방향 암호화키(PTK-TK)를 재설치하여 정보 유출이
가능한 취약점(CVE-2017-13082)
o PeerKey handshake에서 STK(Short-Term Key)를 재설치하여 정보 유출이 가능한 취약점(CVE-2017-13084)
o TDLS(Tunneled Direct-Link Setup) handshake에서 TDLS PeerKey(TPK)를 재설치하여 정보 유출이
가능한 취약점(CVE-2017-13086)
o 무선 네트워크 관리(WNM)가 슬립 모드 응답 프레임을 처리할 때 그룹 암호화키(GTK)를 재설치하여 정보 유출이
가능한 취약점(CVE-2017-13087)
o 무선 네트워크 관리(WNM)가 슬립 모드 응답 프레임을 처리할 때 무결성 그룹 암호화키(IGTK)를 재설치하여 정보 유출이
가능한 취약점(CVE-2017-13088)
##### □ 해결 방안
o Microsoft(완료) [2]
o Ubuntu(완료) [3]
o HostAP(완료) [4]
- 리눅스에서 사용하는 Wi-Fi 데몬(wps_supplicant, hostapd) 업데이트 완료
o Cisco(제품별 패치 진행중) [5]
o Juniper(제품별 패치 진행중) [6]
o Google Android, Apple(iOS, macOS), Redhat 패치 예정
##### □ 기타 문의사항
o 한국인터넷진흥원 인터넷침해대응센터: 국번없이 118
[참고사이트]
[1
Official advisory ↗