{"id":71704,"date":"2020-02-27T20:54:05","date_gmt":"2020-02-27T17:54:05","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimost-v-wi-fi-chipah-cypress-i-broadcom-pozvolyayushhaya-rasshifrovat-trafik"},"modified":"2020-03-03T16:10:37","modified_gmt":"2020-03-03T13:10:37","slug":"uyazvimost-v-wi-fi-chipah-cypress-i-broadcom-pozvolyayushhaya-rasshifrovat-trafik","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-wi-fi-chipah-cypress-i-broadcom-pozvolyayushhaya-rasshifrovat-trafik","title":{"rendered":"Vulnerability in Cypress and Broadcom Wi-Fi chips allows for decrypting traffic.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Researchers from Eset <noindex><a rel=\"nofollow\" href=\"https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2020\/02\/ESET_Kr00k.pdf\">revealed<\/a><\/noindex> at the ongoing conference <noindex><a rel=\"nofollow\" href=\"https:\/\/www.rsaconference.com\/usa\/agenda\/kr00k-how-kracking-amazon-echo-exposed-a-billion-vulnerable-wifi-devices\">RSA 2020<\/a><\/noindex> information about <noindex><a rel=\"nofollow\" href=\"https:\/\/www.eset.com\/int\/kr00k\/\">a vulnerability<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-15126\">CVE-2019-15126<\/a><\/noindex>) in wireless chips from Cypress and Broadcom, allowing for the decryption of intercepted Wi-Fi traffic protected by the WPA2 protocol. The vulnerability is codenamed Kr00k. This issue affects FullMAC chips (where the Wi-Fi stack is implemented on the chip side rather than the driver) used in a wide range of consumer devices, from well-known smartphone manufacturers (Apple, Xiaomi, Google, Samsung) to smart speakers (Amazon Echo, Amazon Kindle), boards (Raspberry Pi 3), and wireless access points (Huawei, ASUS, Cisco).<\/p>\n<p>The vulnerability is caused by improper handling of encryption keys during disconnection (<noindex><a rel=\"nofollow\" href=\"https:\/\/community.cisco.com\/t5\/wireless-mobility-documents\/802-11-association-status-802-11-deauth-reason-codes\/ta-p\/3148055\">disassociation<\/a><\/noindex>) of the device from the access point. Upon disconnection, the session key (PTK) stored in the chip's memory is reset, as no further data will be sent in the current session. The essence of the vulnerability is that data remaining in the transmission buffer (TX) is encrypted using the already cleared key, which consists solely of zeros and can therefore be easily decrypted if intercepted. The empty key is applied only to residual data in the buffer, which is several kilobytes in size. <\/p>\n<p>Thus, the attack is based on artificially sending specific frames that trigger disassociation and intercepting the subsequently sent data. Disassociation is typically used in wireless networks for switching from one access point to another during roaming or when the connection with the current access point is lost. Disassociation can be triggered by sending a control frame, which is transmitted in an unencrypted form and does not require authentication (the attacker only needs to have access to the Wi-Fi signal but does not need to be connected to the wireless network). The attack has only been tested using the WPA2 protocol; the possibility of executing the attack on WPA3 has not been verified.<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2020\/02\/ESET_Kr00k.pdf\"><img decoding=\"async\" alt=\"Vulnerability in Cypress and Broadcom Wi-Fi chips allows for decrypting traffic.\" src=\"\/wp-content\/uploads\/2020\/02\/164a8d4e32d6591de3d4938ec4dc2d30.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>According to preliminary estimates, the vulnerability may potentially affect billions of widely used devices. The issue does not manifest on devices with Qualcomm, Realtek, Ralink, and Mediatek chips. Traffic decryption is possible when a vulnerable client device connects to a problem-free access point, as well as when a non-vulnerable device connects to an access point exhibiting the vulnerability. Many consumer device manufacturers have already released firmware updates addressing the vulnerability (for instance, Apple <noindex><a rel=\"nofollow\" href=\"https:\/\/support.apple.com\/en-us\/HT210721\">addressed<\/a><\/noindex> the vulnerability back in October of last year). <\/p>\n<p>It is important to note that the vulnerability affects encryption at the wireless network level and only allows for the analysis of user-established unencrypted connections, but does not compromise connections with application-level encryption (HTTPS, SSH, STARTTLS, DNS over TLS, VPN, etc.). The risk of an attack is further diminished by the fact that an attacker can only decrypt a few kilobytes of data that were in the transmission buffer at the time of disconnection. For successful interception of confidential data sent over an unencrypted connection, the attacker must either know the exact timing of data transmission or repeatedly initiate disconnections from the access point, which would be noticeable to the user due to constant wireless connection restarts.<\/p>\n<p>Some of the devices tested by Eset for attack vulnerability include:<\/p>\n<ul>\n<li> Amazon Echo 2nd gen\n<li> Amazon Kindle 8th gen\n<li> Apple iPad mini 2\n<li> Apple iPhone 6, 6S, 8, XR\n<li> Apple MacBook Air Retina 13-inch 2018\n<li> Google Nexus 5\n<li> Google Nexus 6\n<li> Google Nexus 6S\n<li> Raspberry Pi 3\n<li> Samsung Galaxy S4 GT-I9505\n<li> Samsung Galaxy S8\n<li> Xiaomi Redmi 3S\n<li> Wireless routers ASUS RT-N12, Huawei B612S-25d, Huawei EchoLife HG8245H, Huawei E5577Cs-321\n<li> <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20200226-wi-fi-info-disclosure\">Cisco access points<\/a><\/noindex>\n<\/ul>\n<p><center><br \/>\n<div class=\"youtube-placeholder\" data-id=\"_40E6WRMRyE\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/_40E6WRMRyE\/hqdefault.jpg\" alt=\"Play video\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><\/center><\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52441\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Eset \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u043d\u0430 \u043f\u0440\u043e\u0445\u043e\u0434\u044f\u0449\u0435\u0439 \u0432 \u044d\u0442\u0438 \u0434\u043d\u0438 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 RSA 2020 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2019-15126) \u0432 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0447\u0438\u043f\u0430\u0445 Cypress \u0438 Broadcom, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0434\u0435\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0447\u0435\u043d\u043d\u044b\u0439 Wi-Fi \u0442\u0440\u0430\u0444\u0438\u043a, \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u044b\u0439 \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 WPA2. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f Kr00k. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043e\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u0435\u0442 \u0447\u0438\u043f\u044b FullMAC (Wi-Fi \u0441\u0442\u0435\u043a \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d \u043d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u0447\u0438\u043f\u0430, \u0430 \u043d\u0435 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430), \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0435 \u0432 \u0448\u0438\u0440\u043e\u043a\u043e\u043c \u0441\u043f\u0435\u043a\u0442\u0440\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":71705,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-71704","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Eset \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u043d\u0430 \u043f\u0440\u043e\u0445\u043e\u0434\u044f\u0449\u0435\u0439 \u0432 \u044d\u0442\u0438 \u0434\u043d\u0438 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-wi-fi-chipah-cypress-i-broadcom-pozvolyayushhaya-rasshifrovat-trafik\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Wi-Fi \u0447\u0438\u043f\u0430\u0445 Cypress \u0438 Broadcom, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Eset \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u043d\u0430 \u043f\u0440\u043e\u0445\u043e\u0434\u044f\u0449\u0435\u0439 \u0432 \u044d\u0442\u0438 \u0434\u043d\u0438 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-wi-fi-chipah-cypress-i-broadcom-pozvolyayushhaya-rasshifrovat-trafik\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-27T17:54:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-03T13:10:37+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerability in Cypress and Broadcom Wi-Fi chips allows for traffic decryption | ProHoster","description":"Researchers from Eset revealed at a conference currently taking place","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-wi-fi-chipah-cypress-i-broadcom-pozvolyayushhaya-rasshifrovat-trafik","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Wi-Fi \u0447\u0438\u043f\u0430\u0445 Cypress \u0438 Broadcom, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u0430\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Eset \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u043d\u0430 \u043f\u0440\u043e\u0445\u043e\u0434\u044f\u0449\u0435\u0439 \u0432 \u044d\u0442\u0438 \u0434\u043d\u0438 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-wi-fi-chipah-cypress-i-broadcom-pozvolyayushhaya-rasshifrovat-trafik","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-27T17:54:05+00:00","article:modified_time":"2020-03-03T13:10:37+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"71704","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 18:57:37","updated":"2022-10-01 10:33:29","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/71704","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=71704"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/71704\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/71705"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=71704"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=71704"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=71704"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}