WPA2 is prone to multiple security weaknesses.
Exploiting these issues may allow an unauthorized user to intercept and manipulate data or disclose sensitive information. This may aid in further attacks.
Information
CVE-2017-13078
CVE-2017-13079
CVE-2017-13080
CVE-2017-13081
CVE-2017-13082
CVE-2017-13084
CVE-2017-13086
CVE-2017-13087
CVE-2017-13088
W1.F1 wpa_supplicant 2.6
W1.F1 wpa_supplicant 2.4
Google Android 7.1.1
Google Android 6.0.1
Google Android 8.0
Google Android 7.1.2
Google Android 7.1.0
Google Android 7.0
Google Android 6.1
Google Android 6.0
Exploit
The researcher created proof-of-concepts to demonstrate these issues. Please see the references for more information.
References:
- stevenhoneyman/wpa_gui (stevenhoneyman)
- Wi-Fi Alliance Home Page (Wi-Fi Alliance)
- Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse (Mathy Vanhoe)
- Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2 (mathyvanhoef)