Don’t Let Kr00k Bend You Out of Shape
Summary
Eset estimated that billions of devices with Broadcom and Cypress Wi-Fi chips send unencrypted traffic over WI-FI when exploited with this vulnerability. Wi-Fi communication typically works by having clients and their connected access point take turns speaking and listening. Additionally, a client or AP sending Management Frames over Wi-Fi must not encrypt this traffic since they haven’t negotiated a key yet. We find Kr00k a less severe vulnerably than KRACK since the client would only send a small amount of traffic unencrypted. Consumers can mitigate against Kr00k, outside of patches from vendors, by configuring the use of WPA3 only, or enabling 802.11w protected Management Frames on their Wi-Fi SSID.
Classifications
industries
Retail
applications
Networking and Cloud
AskAI Classifications
Labels
Cybersecurity Software
SaaS
Network Security
Linked Companies
WatchGuard
$250M to $500M
ESET
$10M to $25M