<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:33:54.061323+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2017-02263</id>
    <title>bdu:2017-02263</title>
    <updated>2026-10-02T10:33:54.226779+00:00</updated>
    <content>bdu:2017-02263</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2017-02263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2017-13077</id>
    <title>Withdrawn: BELL-CVE-2017-13077 — CVE-2017-13077 does not affect BellSoft software</title>
    <updated>2026-10-02T10:33:54.226843+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2017-13077"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2017-ale-014</id>
    <title>certfr-2017-ale-014 — Plusieurs vulnérabilités ont été découvertes dans WPA/WPA2. Il est
possible lors de l'établissement d'une session de co…</title>
    <updated>2026-10-02T10:33:54.226875+00:00</updated>
    <content>certfr-2017-ale-014</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2017-ale-014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2017-avi-358</id>
    <title>certfr-2017-avi-358 — De multiples vulnérabilités ont été découvertes dans Debian sur le
protocole WPA/WPA2. Elles permettent à un attaquant…</title>
    <updated>2026-10-02T10:33:54.226929+00:00</updated>
    <content>certfr-2017-avi-358</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2017-avi-358"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2017-30406</id>
    <title>cnvd-2017-30406</title>
    <updated>2026-10-02T10:33:54.226972+00:00</updated>
    <content>cnvd-2017-30406</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2017-30406"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-77505</id>
    <title>EUVD-2026-77505</title>
    <updated>2026-10-02T10:33:54.227001+00:00</updated>
    <content>EUVD-2026-77505</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-77505"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-13077</id>
    <title>fkie_cve-2017-13077</title>
    <updated>2026-10-02T10:33:54.227028+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-13077"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wxv4-3q58-w3mx</id>
    <title>GHSA-wxv4-3q58-w3mx</title>
    <updated>2026-10-02T10:33:54.227083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wxv4-3q58-w3mx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-13077</id>
    <title>gsd-2017-13077</title>
    <updated>2026-10-02T10:33:54.227111+00:00</updated>
    <content>gsd-2017-13077</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-13077"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-17-318-01</id>
    <title>ICSA-17-318-01 — ICSA-17-318-01_Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update F)</title>
    <updated>2026-10-02T10:33:54.227136+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Wi-Fi protected access (WPA and WPA2) allows reinstallation of the pairwise key in the four-way handshake.CVE-2017-13077 has been assigned to this vulnerability. A CVSS v3 base score of 4.2 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N). Wi-Fi protected access (WPA and WPA2) allows reinstallation of the group temporal key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.CVE-2017-13078 has been assigned to this vulnerability. A CVSS v3 base score of 4.2 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N). Wi-Fi protected access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the integrity group temporal key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients.CVE-2017-13079 has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N). Wi-Fi protected access (WPA and WPA2) allows reinstallation of the group temporal key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.CVE-2017-13080 has been assigned to this vulnerability. A CVSS v3 base score of 4.2 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N). Wi-Fi protected access (WPA and WPA2) that su…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-17-318-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:2053-1</id>
    <title>openSUSE-SU-2020:2053-1 — Security update for wpa_supplicant</title>
    <updated>2026-10-02T10:33:54.227269+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for wpa_supplicant</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:2053-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2017:2911</id>
    <title>RHSA-2017:2911 — Red Hat Security Advisory: wpa_supplicant security update</title>
    <updated>2026-10-02T10:33:54.227310+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>wpa_supplicant: Reinstallation of the pairwise key in the 4-way handshake wpa_supplicant: Reinstallation of the group key in the 4-way handshake wpa_supplicant: Reinstallation of the group key in the group key handshake wpa_supplicant: reinstallation of the group key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2017:2911"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:3380-1</id>
    <title>SUSE-SU-2020:3380-1 — Security update for wpa_supplicant</title>
    <updated>2026-10-02T10:33:54.227349+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for wpa_supplicant</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:3380-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-13077</id>
    <title>UBUNTU-CVE-2017-13077</title>
    <updated>2026-10-02T10:33:54.227403+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: wpa, Ubuntu:16.04:LTS: wpa</p>
<p>Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-13077"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2017-003</id>
    <title>VDE-2017-003 — PHOENIX CONTACT: WLAN enabled devices utilising WPA2 encryption</title>
    <updated>2026-10-02T10:33:54.227440+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.</p>
<p>Update A / Revision 2 - 2017-11-09
* Added a detailed list of affected products</p>
<p>Update B / Revision 3 - 2018-09-24
* Added firmware update information, see section "Solution"</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2017-003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2017-005</id>
    <title>VDE-2017-005 — Pepperl+Fuchs / ecom instruments: WLAN enabled products utilizing WPA2 encryption</title>
    <updated>2026-10-02T10:33:54.227484+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.  
  
ecom instruments is a subsidiary company of PEPPERL+FUCHS.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2017-005"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2019-005</id>
    <title>VDE-2019-005 — Endress+Hauser: WIFI enabled products utilising WPA2</title>
    <updated>2026-10-02T10:33:54.227532+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.
The Field Xpert SFX370 and SFX350 handhelds are manufactured by Pepperl+Fuchs/ecom instruments for Endress+Hauser.
The Advisory for Pepperl+Fuchs/ecom instruments can be found here: VDE-2017-005</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2019-005"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0369</id>
    <title>WID-SEC-W-2025-0369 — IEEE WPA2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:33:54.227570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IEEE WPA2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0369"/>
  </entry>
</feed>
