Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20200527-01-WIFI
HistoryMay 27, 2020 - 12:00 a.m.

Security Advisory - Kr00k Vulnerability in Broadcom Wi-Fi chips

2020-05-2700:00:00
Huawei Technologies
www.huawei.com
74

2.9 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:M/Au:N/C:P/I:N/A:N

3.1 Low

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

0.007 Low

EPSS

Percentile

80.0%

There is an information disclosure vulnerability named Kr00k in Broadcom Wi-Fi chips. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic. (Vulnerability ID: HWPSIRT-2020-02164)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2019-15126.

Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-wifi-en

Affected configurations

Vulners
Node
huaweiap7030deMatchv200r005c20
OR
huaweiap7030deMatchv200r006c00
OR
huaweiap7030deMatchv200r006c10
OR
huaweiap7030deMatchv200r006c20
OR
huaweiap7030deMatchv200r007c10
OR
huaweiap7030deMatchv200r007c20
OR
huaweiap7030deMatchv200r008c00
OR
huaweiap7030deMatchv200r008c10
OR
huaweiap7030deMatchv200r010c00
OR
huaweiap7030deMatchv200r019c00
OR
huaweiap9330dnMatchv200r005c20
OR
huaweiap9330dnMatchv200r006c00
OR
huaweiap9330dnMatchv200r006c10
OR
huaweiap9330dnMatchv200r006c20
OR
huaweiap9330dnMatchv200r007c10
OR
huaweiap9330dnMatchv200r007c20
OR
huaweiap9330dnMatchv200r008c00
OR
huaweiap9330dnMatchv200r008c10
OR
huaweiap9330dnMatchv200r010c00
OR
huaweiap9330dnMatchv200r019c00

2.9 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:M/Au:N/C:P/I:N/A:N

3.1 Low

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

0.007 Low

EPSS

Percentile

80.0%