CVE-2017-13087

Source
Severity High
Remote Yes
Type Man-in-the-middle
Description
A vulnerability has been discovered that allows reinstallation of the group key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame.
Group Package Affected Fixed Severity Status Ticket
AVG-448 hostapd 2.6-5 2.6-6 High Fixed
AVG-447 wpa_supplicant 1:2.6-10 1:2.6-11 High Fixed
Date Advisory Group Package Severity Description
16 Oct 2017 ASA-201710-23 AVG-448 hostapd High man-in-the-middle
16 Oct 2017 ASA-201710-22 AVG-447 wpa_supplicant High man-in-the-middle
References
https://w1.fi/cgit/hostap/commit/?id=87e2db16bafcbc60b8d0016175814a73c1e8ed45