CVE-2019-15126
Broadcom Wi-Fi Devices - 'KR00K Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.
Se detectó un problema en los dispositivos cliente de Broadcom Wi-Fi. Específicamente un tráfico diseñado minuciosamente y sincronizado puede causar errores internos (relacionados con las transiciones de estado) en un dispositivo WLAN que conllevan a un cifrado de Wi-Fi de Capa 2 inapropiado con una consiguiente posibilidad de divulgación de información por medio del aire para un conjunto de tráfico discreto, una vulnerabilidad diferente de CVE-2019-9500, CVE-2019-9501, CVE-2019-9502 y CVE-2019-9503.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-08-17 CVE Reserved
- 2020-02-05 CVE Published
- 2020-03-18 First Exploit
- 2024-05-16 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/156809/Broadcom-Wi-Fi-KR00K-Proof-Of-Concept.html | X_refsource_misc | |
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-003.txt | X_refsource_confirm | |
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-wifi-en | X_refsource_confirm | |
http://www.huawei.com/en/psirt/security-notices/huawei-sn-20200228-01-kr00k-en | X_refsource_confirm | |
https://cert-portal.siemens.com/productcert/pdf/ssa-712518.pdf | X_refsource_confirm | |
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0001 | X_refsource_confirm | |
https://support.apple.com/kb/HT210721 | Third Party Advisory | |
https://support.apple.com/kb/HT210722 | Third Party Advisory | |
https://support.apple.com/kb/HT210788 | X_refsource_confirm | |
https://us-cert.cisa.gov/ics/advisories/icsa-20-224-05 | X_refsource_misc | |
https://www.mist.com/documentation/mist-security-advisory-kr00k-attack-faq | X_refsource_confirm | |
https://www.synology.com/security/advisory/Synology_SA_20_03 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/48233 | 2020-03-18 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Broadcom Search vendor "Broadcom" | Bcm4389 Firmware Search vendor "Broadcom" for product "Bcm4389 Firmware" | - | - |
Affected
| in | Broadcom Search vendor "Broadcom" | Bcm4389 Search vendor "Broadcom" for product "Bcm4389" | - | - |
Safe
|
Broadcom Search vendor "Broadcom" | Bcm43012 Firmware Search vendor "Broadcom" for product "Bcm43012 Firmware" | - | - |
Affected
| in | Broadcom Search vendor "Broadcom" | Bcm43012 Search vendor "Broadcom" for product "Bcm43012" | - | - |
Safe
|
Broadcom Search vendor "Broadcom" | Bcm43013 Firmware Search vendor "Broadcom" for product "Bcm43013 Firmware" | - | - |
Affected
| in | Broadcom Search vendor "Broadcom" | Bcm43013 Search vendor "Broadcom" for product "Bcm43013" | - | - |
Safe
|
Broadcom Search vendor "Broadcom" | Bcm4375 Firmware Search vendor "Broadcom" for product "Bcm4375 Firmware" | - | - |
Affected
| in | Broadcom Search vendor "Broadcom" | Bcm4375 Search vendor "Broadcom" for product "Bcm4375" | - | - |
Safe
|
Broadcom Search vendor "Broadcom" | Bcm43752 Firmware Search vendor "Broadcom" for product "Bcm43752 Firmware" | - | - |
Affected
| in | Broadcom Search vendor "Broadcom" | Bcm43752 Search vendor "Broadcom" for product "Bcm43752" | - | - |
Safe
|
Broadcom Search vendor "Broadcom" | Bcm4356 Firmware Search vendor "Broadcom" for product "Bcm4356 Firmware" | - | - |
Affected
| in | Broadcom Search vendor "Broadcom" | Bcm4356 Search vendor "Broadcom" for product "Bcm4356" | - | - |
Safe
|
Apple Search vendor "Apple" | Ipados Search vendor "Apple" for product "Ipados" | < 13.2 Search vendor "Apple" for product "Ipados" and version " < 13.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | < 13.2 Search vendor "Apple" for product "Iphone Os" and version " < 13.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | < 10.15.1 Search vendor "Apple" for product "Mac Os X" and version " < 10.15.1" | - |
Affected
|