The Temporal Key Integrity Protocol (TKIP) implementation in unspecified Cisco...
Vulnerability Description
The Temporal Key Integrity Protocol (TKIP) implementation in unspecified Cisco products and other vendors' products, as used in WPA and WPA2 on Wi-Fi networks, has insufficient countermeasures against certain crafted and replayed packets, which makes it easier for remote attackers to decrypt packets from an access point (AP) to a client and spoof packets from an AP to a client, and conduct ARP poisoning attacks or other attacks, as demonstrated by tkiptun-ng.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-5230
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.immunitysec.com/pipermail/dailydave/2008-November/005413.html
- http://arstechnica.com/articles/paedia/wpa-cracked.ars
- http://trac.aircrack-ng.org/svn/trunk/src/tkiptun-ng.c
- http://www.cisco.com/en/US/products/products_security_response09186a0080a30036.html
- http://radajo.blogspot.com/2008/11/wpatkip-chopchop-attack.html
- http://dl.aircrack-ng.org/breakingwepandwpa.pdf
- http://www.aircrack-ng.org/doku.php?id=tkiptun-ng
- http://www.securityfocus.com/bid/32164
More from cisco
View All →Affected Vendor
cisco
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.