PT-2020-1885 · Cypress+2 · Cypress Wi-Fi Chips+2
Published
2020-02-05
·
Updated
2024-01-15
·
CVE-2019-15126
CVSS v3.1
3.1
Low
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Broadcom and Cypress Wi-Fi chips (affected versions not specified)
Description
The issue is related to errors in synchronization when using a shared resource in Wi-Fi chipsets from Broadcom. This can allow a remote attacker to gain unauthorized access to protected information. The vulnerability, known as Kr00k, affects the encryption of Wi-Fi devices, allowing unauthorized decryption of some WPA2-encrypted traffic. It is estimated to affect over a billion Wi-Fi devices, including those from major manufacturers such as Apple, Xiaomi, Google, and Samsung. The problem encompasses FullMAC chips, which are used in a wide range of consumer devices, from smartphones to smart speakers and wireless access points.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Broadcom Wi-Fi Chips
Cypress Wi-Fi Chips
Suse