CVE-2019-15126
Summary
| CVE | CVE-2019-15126 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-05 17:15:00 UTC |
| Updated | 2020-08-11 19:15:00 UTC |
| Description | An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Synology Inc. |
CONFIRM |
www.synology.com |
|
| Security Advisory - Kr00k Vulnerability in Broadcom Wi-Fi chips |
CONFIRM |
www.huawei.com |
|
| Broadcom Wi-Fi KR00K Proof Of Concept ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| Wi-Fi Protected Network and Wi-Fi Protected Network 2 Information Disclosure Vulnerability |
CISCO |
tools.cisco.com |
|
| About the security content of macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006 - Apple Support |
CONFIRM |
support.apple.com |
Third Party Advisory |
| www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-003.txt |
CONFIRM |
www.arubanetworks.com |
|
| Siemens SIMATIC, SIMOTICS | CISA |
MISC |
us-cert.cisa.gov |
|
| Security Advisory |
CONFIRM |
psirt.global.sonicwall.com |
|
| About the security content of iOS 13.2 and iPadOS 13.2 - Apple Support |
CONFIRM |
support.apple.com |
Third Party Advisory |
| About the security content of macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra - Apple Support |
CONFIRM |
support.apple.com |
|
| cert-portal.siemens.com/productcert/pdf/ssa-712518.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| Mist Security Advisory - Kr00k Attack & FAQ - Mist Systems |
CONFIRM |
www.mist.com |
|
| Security Notice - Statement About the Vulnerability Kr00k in Wi-Fi Chips |
CONFIRM |
www.huawei.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 751481 SUSE Enterprise Linux Security Update for bcm43xx-firmware (SUSE-SU-2021:4003-1)
- 751567 SUSE Enterprise Linux Security Update for kernel-firmware (SUSE-SU-2021:4200-1)
- 751573 OpenSUSE Security Update for kernel-firmware (openSUSE-SU-2021:1648-1)
- 751600 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:0068-1)
- 751602 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:0080-1)
- 751695 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:0367-1)
- 751697 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:0366-1)
- 751701 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2022:0366-1)
- 751702 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:0371-1)