CVE-2017-13077: KRACK
A key reinstallation vulnerability in the WPA2 4-way handshake used to secure Wi-Fi networks. A man-in-the-middle attacker can manipulate and replay a retransmitted handshake message so a client reinstalls an already-in-use encryption key, resetting its associated nonce and allowing the attacker to decrypt, and in some configurations forge or inject, network traffic.
View the authoritative record on NVD ↗Affected software
- WPA2-capable Wi-Fi client and access point implementations across essentially all vendors as of the October 2017 disclosure
How it's exploited
Position as a man-in-the-middle between a Wi-Fi client and its access point (for example via a channel-based MITM technique) and block or replay the retransmitted message 3 of the WPA2 4-way handshake, tricking the client into reinstalling a key it has already installed, which resets nonce and replay counters and allows the attacker to decrypt captured packets.
Severity
CVE-2017-13077 carries a CVSS 3.0 base score of 6.8, rated Medium. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2017-13077 is categorized under CWE-330, the general weakness pattern behind this specific vulnerability.
How TurboPentest tests for this (white-box)
This weakness (Use of Insufficiently Random Values) is caught by white-box static analysis when you connect a GitHub repo: IntegSec's Opengrep SAST rule pack carries 5 rules for it, flagging the issue directly in your source code as part of the pentest.
Remediation
Apply the vendor patch implementing the IEEE-published fix that prevents key reinstallation (most major operating system and access point vendors shipped patches within weeks of disclosure); migrating to WPA3, which addresses this class of handshake weakness structurally, closes it for good.
Frequently asked questions
What is CVE-2017-13077?
A key reinstallation vulnerability in the WPA2 4-way handshake used to secure Wi-Fi networks. A man-in-the-middle attacker can manipulate and replay a retransmitted handshake message so a client reinstalls an already-in-use encryption key, resetting its associated nonce and allowing the attacker to decrypt, and in some configurations forge or inject, network traffic.
How severe is CVE-2017-13077?
CVE-2017-13077 has a CVSS 3.0 base score of 6.8 out of 10, rated Medium.
What software is affected by CVE-2017-13077?
CVE-2017-13077 affects WPA2-capable Wi-Fi client and access point implementations across essentially all vendors as of the October 2017 disclosure.
How do you fix CVE-2017-13077?
Apply the vendor patch implementing the IEEE-published fix that prevents key reinstallation (most major operating system and access point vendors shipped patches within weeks of disclosure); migrating to WPA3, which addresses this class of handshake weakness structurally, closes it for good.
Where is the authoritative record for CVE-2017-13077?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2017-13077 at https://nvd.nist.gov/vuln/detail/CVE-2017-13077, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest