ICSA-17-318-01: ICSA-17-318-01_Siemens SCALANCE, SIMATIC, RUGGEDCOM, and SINAMICS Products (Update F)
CISA advisory · released 2017-11-14
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 7, 2019-04-09 (final)
CISA's summary
Summary: Mathy Vanhoef, of the Katholieke Universiteit Leuven in Belgium, discovered these vulnerabilities.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | SIMATIC RF650M | < 22.3.5.16 |
| Siemens | SCALANCE W-700 (IEEE 802.11a/b/g) | vers:all/* |
| Siemens | SIMATIC Mobile Panel 277(F) IWLAN | vers:all/* |
| Siemens | RUGGEDCOM RS9xxW | vers:all/* |
| Siemens | SIMATIC RF350M | < 22.3.5.16 |
| Siemens | SINAMICS v20 Smart Access Module | < 01.03.01 |
| Siemens | SCALANCE WLC712 | < 9.21.19.003 |
| Siemens | SCALANCE W-700 (IEEE 802.11n) | < 6.2.1 |
| Siemens | SCALANCE W1750D | < 6.5.1.5-4.3.1.8 |
| Siemens | RUGGEDCOM RX1400 with WLAN interface | < 2.11.2 |
| Siemens | SIMATIC IWLAN-PB/LINK | vers:all/* |
| Siemens | SCALANCE WLC711 | < 9.21.19.003 |
| Siemens | SIMATIC ET200 PRO IM154-6 PN IWLAN | vers:all/* |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2017-13077 — CVE-2017-13077 · CWE-322
Wi-Fi protected access (WPA and WPA2) allows reinstallation of the pairwise key in the four-way handshake.CVE-2017-13077 has been assigned to this vulnerability. A CVSS v3 base score of 4.2 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
- CVE-2017-13078 — CVE-2017-13078 · CWE-322
Wi-Fi protected access (WPA and WPA2) allows reinstallation of the group temporal key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.CVE-2017-13078 has been assigned to this vulnerability. A CVSS v3 base score of 4.2 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
- CVE-2017-13079 — CVE-2017-13079 · CWE-322
Wi-Fi protected access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the integrity group temporal key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients.CVE-2017-13079 has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N).
- CVE-2017-13080 — CVE-2017-13080 · CWE-322
Wi-Fi protected access (WPA and WPA2) allows reinstallation of the group temporal key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.CVE-2017-13080 has been assigned to this vulnerability. A CVSS v3 base score of 4.2 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
- CVE-2017-13081 — CVE-2017-13081 · CWE-322
Wi-Fi protected access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the integrity group temporal key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.CVE-2017-13081 has been assigned to this vulnerability. A CVSS v3 base score of 4.2 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
- CVE-2017-13082 — CVE-2017-13082 · CWE-322
Wi-Fi protected access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the pairwise transient key (PTK) temporal key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.CVE-2017-13082 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
- CVE-2017-13084 — CVE-2017-13084 · CWE-322
Wi-Fi protected access (WPA and WPA2) allows reinstallation of the station-to-station-link (STSL) transient key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.CVE-2017-13084 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
- CVE-2017-13086 — CVE-2017-13086 · CWE-322
Wi-Fi protected access (WPA and WPA2) allows reinstallation of the tunneled direct-link setup (TDLS) peer key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.CVE-2017-13086 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
- CVE-2017-13087 — CVE-2017-13087 · CWE-322
Wi-Fi protected access (WPA and WPA2) that support 802.11v allows reinstallation of the group temporal key (GTK) when processing a wireless network management (WNM) sleep mode response frame, allowing an attacker within radio range to replay frames from access points to clients.CVE-2017-13087 has been assigned to this vulnerability. A CVSS v3 base score of 4.2 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
- CVE-2017-13088 — CVE-2017-13088 · CWE-322
Wi-Fi protected access (WPA and WPA2) that support 802.11v allows reinstallation of the integrity group temporal key (IGTK) when processing a wireless network management (WNM) sleep mode response frame, allowing an attacker within radio range to replay frames from access points to clients.CVE-2017-13088 has been assigned to this vulnerability. A CVSS v3 base score of 4.2 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
Acknowledgments, as the advisory lists them
- Mathy Vanhoef, the Katholieke Universiteit Leuven in Belgium: discovering these vulnerabilities
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.