<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:37:11 +0000</lastBuildDate>
    <item>
      <title>bdu:2017-02268</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2017-02268</link>
      <description>bdu:2017-02268</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2017-02268</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2017-13082 — CVE-2017-13082 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2017-13082</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2017-13082</guid>
    </item>
    <item>
      <title>certfr-2017-ale-014 — Plusieurs vulnérabilités ont été découvertes dans WPA/WPA2. Il est
possible lors de l'établissement d'une session de co…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2017-ale-014</link>
      <description>certfr-2017-ale-014</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2017-ale-014</guid>
    </item>
    <item>
      <title>certfr-2017-avi-358 — De multiples vulnérabilités ont été découvertes dans Debian sur le
protocole WPA/WPA2. Elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2017-avi-358</link>
      <description>certfr-2017-avi-358</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2017-avi-358</guid>
    </item>
    <item>
      <title>cnvd-2017-30401</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-30401</link>
      <description>cnvd-2017-30401</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-30401</guid>
    </item>
    <item>
      <title>EUVD-2026-77548</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-77548</link>
      <description>EUVD-2026-77548</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-77548</guid>
    </item>
    <item>
      <title>fkie_cve-2017-13082</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-13082</link>
      <description>&lt;p&gt;Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-13082</guid>
    </item>
    <item>
      <title>GHSA-fx3c-8pqx-5v4c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fx3c-8pqx-5v4c</link>
      <description>&lt;p&gt;Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fx3c-8pqx-5v4c</guid>
    </item>
    <item>
      <title>gsd-2017-13082</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-13082</link>
      <description>gsd-2017-13082</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-13082</guid>
    </item>
    <item>
      <title>ICSA-17-299-02 — Rockwell Automation Stratix 5100 (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-17-299-02</link>
      <description>&lt;p&gt;Key reinstallation attacks (KRACK) work against the four-way handshake of the WPA2 protocol. KRACK takes advantage of the retransmission of a handshake message to prompt the installation of the same encryption key every time it receives message 3 from the access point. Retransmission of the handshake message from the access point occurs if a proper client acknowledgement is not received to the initial message; retransmission resets the nonce value and replay counter to their initial values. A malicious actor could force these nonce resets by replaying the appropriate handshake message, which could allow for injection and decryption of arbitrary packets, hijacking of TCP connections, injection of HTTP content, or replaying of unicast or multicast data frames on the targeted device.CVE-2017-13082 has been assigned to this vulnerability. A CVSS v3 base score of 6.9 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Key reinstallation attacks (KRACK) work against the four-way handshake of the WPA2 protocol. KRACK takes advantage of the retransmission of a handshake message to prompt the installation of the same encryption key every time it receives message 3 from the access point. Retransmission of the handshake message from the access point occurs if a proper client acknowledgement is not received to the initial message; retransmission resets the nonce value and replay counter to their initial values. A malicious actor could force these nonce resets by replaying the appropriate handshake message, which could allow for injection and decryption of arbitrary packets, hijacking of TCP connections, injection of HTTP content, or replaying of unicast or multicast data frames on the targeted device.CVE-2017-13082 has been assigned to this vulnerability. A CVSS v3 base score of 6.9 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-17-299-02</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:0222-1 — Security update for hostapd</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0222-1</link>
      <description>&lt;p&gt;Security update for hostapd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for hostapd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:0222-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:3380-1 — Security update for wpa_supplicant</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:3380-1</link>
      <description>&lt;p&gt;Security update for wpa_supplicant&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for wpa_supplicant&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:3380-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-13082</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-13082</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: wpa, Ubuntu:16.04:LTS: wpa&lt;/p&gt;
&lt;p&gt;Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: wpa, Ubuntu:16.04:LTS: wpa&lt;/p&gt;
&lt;p&gt;Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-13082</guid>
    </item>
    <item>
      <title>VDE-2017-005 — Pepperl+Fuchs / ecom instruments: WLAN enabled products utilizing WPA2 encryption</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2017-005</link>
      <description>&lt;p&gt;Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.  
  
ecom instruments is a subsidiary company of PEPPERL+FUCHS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.  
  
ecom instruments is a subsidiary company of PEPPERL+FUCHS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2017-005</guid>
    </item>
    <item>
      <title>VDE-2019-005 — Endress+Hauser: WIFI enabled products utilising WPA2</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-005</link>
      <description>&lt;p&gt;Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.
The Field Xpert SFX370 and SFX350 handhelds are manufactured by Pepperl+Fuchs/ecom instruments for Endress+Hauser.
The Advisory for Pepperl+Fuchs/ecom instruments can be found here: VDE-2017-005&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.
The Field Xpert SFX370 and SFX350 handhelds are manufactured by Pepperl+Fuchs/ecom instruments for Endress+Hauser.
The Advisory for Pepperl+Fuchs/ecom instruments can be found here: VDE-2017-005&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-005</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0369 — IEEE WPA2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0369</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IEEE WPA2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IEEE WPA2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0369</guid>
    </item>
  </channel>
</rss>
