Vulnerability Name:

CVE-2019-15126 (CCN-175911)

Assigned:2019-10-28
Published:2019-10-28
Updated:2020-08-11
Summary:An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.
CVSS v3 Severity:3.1 Low (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
2.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
5.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.9 Low (CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
6.1 Medium (CCN CVSS v2 Vector: AV:A/AC:L/Au:N/C:C/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-367
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2019-15126

Source: MISC
Type: UNKNOWN
http://packetstormsecurity.com/files/156809/Broadcom-Wi-Fi-KR00K-Proof-Of-Concept.html

Source: CONFIRM
Type: UNKNOWN
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-003.txt

Source: CONFIRM
Type: UNKNOWN
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-wifi-en

Source: CONFIRM
Type: UNKNOWN
http://www.huawei.com/en/psirt/security-notices/huawei-sn-20200228-01-kr00k-en

Source: CONFIRM
Type: UNKNOWN
https://cert-portal.siemens.com/productcert/pdf/ssa-712518.pdf

Source: XF
Type: UNKNOWN
broadcom-cve201915126-info-disc(175911)

Source: CCN
Type: Packet Storm Security [03-19-2020]
Broadcom Wi-Fi KR00K Proof Of Concept

Source: CONFIRM
Type: UNKNOWN
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0001

Source: CCN
Type: Apple security document HT210721
About the security content of iOS 13.2 and iPadOS 13.2

Source: CONFIRM
Type: Third Party Advisory
https://support.apple.com/kb/HT210721

Source: CONFIRM
Type: Third Party Advisory
https://support.apple.com/kb/HT210722

Source: CONFIRM
Type: UNKNOWN
https://support.apple.com/kb/HT210788

Source: CCN
Type: Cisco Security Advisory cisco-sa-20200226-wi-fi-info-disclosure
Wi-Fi Protected Network and Wi-Fi Protected Network 2 Information Disclosure Vulnerability

Source: CISCO
Type: UNKNOWN
20200227 Wi-Fi Protected Network and Wi-Fi Protected Network 2 Information Disclosure Vulnerability

Source: MISC
Type: UNKNOWN
https://us-cert.cisa.gov/ics/advisories/icsa-20-224-05

Source: CCN
Type: Broadcom Web site
Broadcom Wireless driver

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [03-18-2020]

Source: CONFIRM
Type: UNKNOWN
https://www.mist.com/documentation/mist-security-advisory-kr00k-attack-faq/

Source: CONFIRM
Type: UNKNOWN
https://www.synology.com/security/advisory/Synology_SA_20_03

Vulnerable Configuration:Configuration 1:
  • cpe:/o:apple:ipados:*:*:*:*:*:*:*:* (Version < 13.2)
  • OR cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:* (Version < 13.2)
  • OR cpe:/o:apple:mac_os_x:*:*:*:*:*:*:*:* (Version < 10.15.1)

  • Configuration 2:
  • cpe:/o:broadcom:bcm4389_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:broadcom:bcm4389:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:broadcom:bcm43012_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:broadcom:bcm43012:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:broadcom:bcm43013_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:broadcom:bcm43013:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:broadcom:bcm4375_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:broadcom:bcm4375:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:broadcom:bcm43752_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:broadcom:bcm43752:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:broadcom:bcm4356_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:broadcom:bcm4356:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:cisco:ip_phone_8861:-:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:wireless_ip_phone_8821:-:*:*:*:*:*:*:*
  • OR cpe:/o:apple:ios:13.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:ipados:13.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:3554
    P
    libXcursor1-1.1.14-4.6.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94666
    P
    libmspack-devel-0.6-3.14.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:125394
    P
    Security update for the Linux Kernel (Important)
    2022-02-11
    oval:org.opensuse.security:def:125797
    P
    Security update for the Linux Kernel (Important)
    2022-02-11
    oval:org.opensuse.security:def:127358
    P
    Security update for the Linux Kernel (Important)
    2022-02-11
    oval:org.opensuse.security:def:125120
    P
    Security update for the Linux Kernel (Important)
    2022-02-11
    oval:org.opensuse.security:def:126960
    P
    Security update for the Linux Kernel (Important)
    2022-02-11
    oval:org.opensuse.security:def:21845
    P
    Security update for the Linux Kernel (Important)
    2022-01-17
    oval:org.opensuse.security:def:4742
    P
    Security update for the Linux Kernel (Important)
    2022-01-17
    oval:org.opensuse.security:def:34682
    P
    Security update for the Linux Kernel (Important)
    2022-01-14
    oval:org.opensuse.security:def:60505
    P
    Security update for the Linux Kernel (Important)
    2022-01-14
    oval:org.opensuse.security:def:6188
    P
    Security update for the Linux Kernel (Important)
    2022-01-14
    oval:org.opensuse.security:def:61117
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:6359
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:4701
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:60504
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:35294
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:26227
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:19626
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:6177
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:5357
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:34681
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:20589
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:4305
    P
    Security update for the Linux Kernel (Important)
    2022-01-13
    oval:org.opensuse.security:def:73765
    P
    Security update for kernel-firmware (Low)
    2021-12-30
    oval:org.opensuse.security:def:111191
    P
    Security update for kernel-firmware (Low)
    2021-12-30
    oval:org.opensuse.security:def:60443
    P
    Security update for kernel-firmware (Low)
    2021-12-30
    oval:org.opensuse.security:def:64643
    P
    Security update for kernel-firmware (Low)
    2021-12-30
    oval:org.opensuse.security:def:108045
    P
    Security update for kernel-firmware (Low)
    2021-12-30
    oval:org.opensuse.security:def:5942
    P
    Security update for kernel-firmware (Low)
    2021-12-30
    oval:org.opensuse.security:def:101379
    P
    Security update for kernel-firmware (Low)
    2021-12-30
    oval:org.opensuse.security:def:117559
    P
    Security update for kernel-firmware (Low)
    2021-12-30
    oval:org.opensuse.security:def:34620
    P
    Security update for kernel-firmware (Low)
    2021-12-30
    oval:org.opensuse.security:def:42155
    P
    Security update for kernel-firmware (Low)
    2021-12-30
    oval:org.opensuse.security:def:34012
    P
    Security update for bcm43xx-firmware (Important)
    2021-12-13
    oval:org.opensuse.security:def:5933
    P
    Security update for bcm43xx-firmware (Important)
    2021-12-13
    oval:org.opensuse.security:def:89490
    P
    Security update for bcm43xx-firmware (Important)
    2021-12-13
    oval:org.opensuse.security:def:127205
    P
    Security update for bcm43xx-firmware (Important)
    2021-12-13
    oval:org.opensuse.security:def:59577
    P
    Security update for bcm43xx-firmware (Important)
    2021-12-13
    oval:org.opensuse.security:def:34611
    P
    Security update for bcm43xx-firmware (Important)
    2021-12-13
    oval:org.opensuse.security:def:59835
    P
    Security update for bcm43xx-firmware (Important)
    2021-12-13
    oval:org.opensuse.security:def:126808
    P
    Security update for bcm43xx-firmware (Important)
    2021-12-13
    oval:org.opensuse.security:def:33754
    P
    Security update for bcm43xx-firmware (Important)
    2021-12-13
    oval:org.opensuse.security:def:89232
    P
    Security update for bcm43xx-firmware (Important)
    2021-12-13
    oval:org.opensuse.security:def:60434
    P
    Security update for bcm43xx-firmware (Important)
    2021-12-13
    BACK
    apple ipados *
    apple iphone os *
    apple mac os x *
    broadcom bcm4389 firmware -
    broadcom bcm4389 -
    broadcom bcm43012 firmware -
    broadcom bcm43012 -
    broadcom bcm43013 firmware -
    broadcom bcm43013 -
    broadcom bcm4375 firmware -
    broadcom bcm4375 -
    broadcom bcm43752 firmware -
    broadcom bcm43752 -
    broadcom bcm4356 firmware -
    broadcom bcm4356 -
    cisco ip phone 8861 -
    cisco wireless ip phone 8821 -
    apple ios 13.2
    apple ipados 13.2