The Key Reinstallation Attack (KRACK) exploits weaknesses in Wi‑Fi Protected Access II (WPA2) key management. Under specific conditions, an attacker within radio range may be able to replay, decrypt or forge packets. Exploitation requires proximity and specific conditions and does not enable persistent device compromise.
Mitigation depends on your system configuration. For Linux®-hosted systems, WPA2 key management can be implemented in wpa_supplicant, so mitigation requires updating wpa_supplicant. For other systems, WPA2 key management is implemented in device firmware, so mitigation requires updating the device firmware. Refer to the Affected Products and Resolution table for the firmware versions that include fixes for this vulnerability.
This page addresses the following KRACK‑related vulnerabilities identified by Common Vulnerabilities and Exposures (CVEs), which impact WPA2 implementations at the protocol and implementation level:
CVE‑2017‑13077: Reinstallation of the Pairwise Encryption Key (PTK‑TK) in the 4-way handshake
CVE‑2017‑13078: Reinstallation of the Group Key (GTK) in the 4-way handshake
CVE‑2017‑13079: Reinstallation of the Integrity Group Key (IGTK) in the four-way handshake
CVE‑2017‑13080: Reinstallation of the GTK in the group key handshake
CVE‑2017‑13081: Reinstallation of the IGTK in the group key handshake
CVE‑2017‑13082: Accepting retransmitted fast Basic Service Set (BSS) transition reassociation requests and reinstalling the PTK-TK while processing it
CVE‑2017‑13084: Reinstallation of the STK in the PeerKey handshake
CVE‑2017‑13086: Reinstallation of the Tunneled Direct-Link Setup (TDLS) PeerKey (TPK) key in the TDLS handshake
CVE-2017-13087: Reinstallation of the GTK when processing a Wireless Network Management (WNM) sleep mode response frame
CVE‑2017‑13088: Reinstallation of the IGTK when processing a WNM sleep mode response frame
Note: Not all KRACK CVEs apply to every device type. Applicability depends on supported protocol features, such as IGTK, and implementation details.
Some of our wireless products are also affected by a related vulnerability. This vulnerability allows non-Quality-of-Service (non-QoS) frames to bypass Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP) and Temporal Key Integrity Protocol (TKIP) replay detection if a Block Acknowledgement (Block Ack) session is active. It does not have a CVE assigned so it is listed as “CCMP/TKIP Replay” in the affected products table.
Last Updated: June 30, 2026
Only products listed in the Affected Products and Resolution section of this advisory are known to be affected by these vulnerabilities.
Reference documentation includes the following third-party materials:
CERT vulnerability note: KRACK – Key Reinstallation Attacks VU#228519
Official KRACK disclosure site
Live Chat