cancel
Showing results for 
Search instead for 
Did you mean: 

KRACK attack on WPA2

KRACK attack on WPA2

Johannes_Dennin
New Contributor
Hello everyone,
I have some questions due to the expected disclosure today on the attack possible on WPA2 SSIDs.
US-CERT has become aware of several key management vulnerabilities in the 4-way handshake of the Wi-Fi Protected Access II (WPA2) security protocol. The impact of exploiting these vulnerabilities includes decryption, packet replay, TCP connection hijacking, HTTP content injection, and others. Note that as protocol-level issues, most or all correct implementations of the standard will be affected. The CERT/CC and the reporting researcher KU Leuven, will be publicly disclosing these vulnerabilities on 16 October 2017.


Link: https://arstechnica.com/information-technology/2017/10/severe-flaw-in-wpa2-protocol-leaves-wi-fi-tra...

- Is Extreme aware of this?
- Are Fixes ready to be released?
- Is a software fix sufficient or does hardware need to be replaced?

Thanks and best regards,

Johannes
84 REPLIES 84

AP650 is still supported by 5.9.0.2 and 5.9.1.0 , so the better way is to switch from 5.8 to 5.9 .

The problem only concern RFS7000 that last firmware is 5.8.5 and actually has no plan to get a 5.8.6.7.

maybe a solution is to drive AP650 with firmware 5.8.6.7 with RFS version 5.8.5 .
the AP650 is part of AP6532 firmware as they're are similar.

Drew_C
Valued Contributor III
Hello everyone, I added some release and schedule updates to the VN earlier today.
VN 2017-005 - KRACK, WPA2 Protocol Flaw

Drew_C
Valued Contributor III
Hi Andrew - I've updated the article with information on both of these versions. Sorry for the confusion and thank you for pointing out the information gap.

Please update the article VN 2017-005 - KRACK, WPA2 Protocol Flaw to include the fact that 5.8.6.8 corrects KRACK on Client Bridge installations. There is some confusion surrounding the fact that TWO versions were released for KRACK fix (5.8.6.7 and 5.8.6.8).

Ronald_Dvorak
Honored Contributor
Looks like I'll pass on that and wait for the version that incl the ACWS fix.

Thanks,
Ron
GTM-P2G8KFN