| Vulnerability Name: | CVE-2008-5230 (CCN-46990) | ||||||||
| Assigned: | 2008-11-07 | ||||||||
| Published: | 2008-11-07 | ||||||||
| Updated: | 2008-12-03 | ||||||||
| Summary: | The Temporal Key Integrity Protocol (TKIP) implementation in unspecified Cisco products and other vendors' products, as used in WPA and WPA2 on Wi-Fi networks, has insufficient countermeasures against certain crafted and replayed packets, which makes it easier for remote attackers to decrypt packets from an access point (AP) to a client and spoof packets from an AP to a client, and conduct ARP poisoning attacks or other attacks, as demonstrated by tkiptun-ng. The impact of this vulnerability has yet to be determined. The full list of affected platforms is subject to change. The NVD will continue to monitor this vulnerability and adjust the configurations as needed. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:W/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:POC/RL:W/RC:C)
| ||||||||
| Vulnerability Type: | CWE-310 | ||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||
| References: | Source: MISC Type: UNKNOWN http://arstechnica.com/articles/paedia/wpa-cracked.ars Source: MITRE Type: CNA CVE-2008-5230 Source: CCN Type: Aircrack-ng Web site Practical attacks against WEP and WPA Source: MISC Type: Exploit http://dl.aircrack-ng.org/breakingwepandwpa.pdf Source: CCN Type: Dailydave Mailing List, Fri Nov 7 01:54:50 EST 2008 All Ur WiFi(WPA) R Belong 2 PacSec Source: MLIST Type: UNKNOWN [dailydave] 20081107 All Ur WiFi(WPA) R Belong 2 PacSec Source: MISC Type: UNKNOWN http://radajo.blogspot.com/2008/11/wpatkip-chopchop-attack.html Source: MISC Type: Exploit http://trac.aircrack-ng.org/svn/trunk/src/tkiptun-ng.c Source: MISC Type: UNKNOWN http://www.aircrack-ng.org/doku.php?id=tkiptun-ng Source: CCN Type: cisco-sr-20081121-wpa Cisco Security Response: Cisco Response to TKIP Encryption Weakness Source: CISCO Type: UNKNOWN 20081121 Cisco Response to TKIP Encryption Weakness Source: CCN Type: OSVDB ID: 53098 Cisco Multiple Products Temporal Key Integrity Protocol (TKIP) Encryption Weakness Source: BID Type: UNKNOWN 32164 Source: CCN Type: BID-32164 Wi-Fi Protected Access (WPA) Encryption Standard TKIP Encryption Bypass Vulnerability Source: XF Type: UNKNOWN wpa-tkip-weak-security(46990) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||