CVE-2019-15126, also known as Kr00k, affects Broadcom and Apple Wi-Fi client devices. This vulnerability allows an attacker to decrypt a discrete set of Wi-Fi traffic due to improper Layer 2 encryption caused by specially timed and crafted traffic. With a CVSS score of 3.1 (LOW), it requires adjacent network access and high attack complexity, leading to potential information disclosure. While not in the KEV catalog, public exploit code (EDB-48233) exists, and it has garnered significant community discussion and media coverage, indicating active interest and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.2CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 13.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.15.1CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:broadcom:bcm4389_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:broadcom:bcm43012_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MITRE: CVE-2019-15126 Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device
Feb 14, 2023Kr00k NO IMPACT Notification
Mar 3, 2020linux-firmware: Transmission of data encrypted with an all-zero session key after disassociation
Feb 5, 2020