Wi-Fi Security Protocol Key Reinstallation Attack (KRACK) Impact on RSA Products
Originally Published: 2017-10-23
Article Number
Applies To
CVE Identifier(s)
Article Summary
- CVE-2017-13077 - Reinstallation of the pairwise encryption key (PTK-TK) in the 4-way handshake
- CVE-2017-13078 - Reinstallation of the group key (GTK) in the 4-way handshake
- CVE-2017-13079 - Reinstallation of the integrity group key (IGTK) in the 4-way handshake
- CVE-2017-13080 - Reinstallation of the group key (GTK) in the group key handshake
- CVE-2017-13081 - Reinstallation of the integrity group key (IGTK) in the group key handshake
- CVE-2017-13082 - Accepting a retransmitted Fast BSS Transition (FT) Reassociation Request and reinstalling the pairwise encryption key (PTK-TK) while processing it
- CVE-2017-13084 - Reinstallation of the STK key in the PeerKey handshake
- CVE-2017-13086 - Reinstallation of the Tunneled Direct-Link Setup (TDLS) PeerKey (TPK) key in the TDLS handshake
- CVE-2017-13087 - Reinstallation of the group key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame
- CVE-2017-13088 - Reinstallation of the integrity group key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame
Resolution
Notes
For information on Dell EMC products, see https://support.emc.com/kb/511474
References:
- Research paper entitled "Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2": https://papers.mathyvanhoef.com/ccs2017.pdf
- Research website: https://www.krackattacks.com/
- CERT/CC Vulnerability Note VU#228519: https://www.kb.cert.org/vuls/id/228519
Disclaimer
Related Articles
Customer getting collected on every login to FI website 3Number of Views How to move BINs from one FI to another in same region 20Number of Views How to set up a cron job to move files older than x days to a remote location daily in RSA Authentication Manager 8.x 7Number of Views Error message of passwd had "2" usages of 0, but expected 1, when installing RSA Identity Governance & Lifecycle 34Number of Views Unable to run sqlplus command as root or any other user except oracle on RSA Identity Governance and Lifecycle 6.8.x and a… 40Number of Views
Trending Articles
RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide AFX Server stuck in 'Not running' State, with error 'timed out waiting for AFX applications to start' Add, Delete, and Test the Connection for an Identity Source in Cloud Access Service
Don't see what you're looking for?