CVE-2017-13086: Medium severity android vulnerability
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
Other sources
Wi-Fi Protected Access II (WPA2) handshake traffic can be manipulated to induce nonce and session key reuse, resulting in key reinstallation by a victim wireless access point (AP) or client. After establishing a man-in-the-middle position between an AP and client, an attacker can selectively manipulate the timing and transmission of messages in the WPA2 Tunneled Direct-Link Setup (TDLS) PeerKey (TPK) handshake, resulting in out-of-sequence reception or retransmission of messages.
An attacker within the wireless communications range of an affected AP and client may leverage these vulnerabilities to conduct attacks that are dependent on the data confidentiality protocol being used. Attacks may include arbitrary packet decryption and injection, TCP connection hijacking, HTTP content injection, or the replay of unicast, broadcast, and multicast frames.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13086?
CVE-2017-13086 is classified as a medium severity vulnerability because it allows attackers in close proximity to exploit the TDLS handshake.
How do I fix CVE-2017-13086?
To fix CVE-2017-13086, update the affected software to the latest version that addresses this vulnerability.
What types of devices are affected by CVE-2017-13086?
Devices affected by CVE-2017-13086 include certain versions of Android, Ubuntu, Debian, FreeBSD, openSUSE, and Red Hat Enterprise Linux.
Can CVE-2017-13086 be exploited remotely?
No, CVE-2017-13086 can only be exploited by attackers within radio range of the vulnerable device.
What protocol is impacted by CVE-2017-13086?
CVE-2017-13086 impacts the Wi-Fi Protected Access II (WPA2) protocol, specifically during the Tunneled Direct-Link Setup (TDLS) handshake.