We detect you are using an unsupported browser. For the best experience, please visit the site using Chrome, Firefox, Safari, or Edge. X
Maximize Your Experience: Reap the Personalized Advantages by Completing Your Profile to Its Fullest. Update Here
Stay in the loop with the latest from Microchip. Update your profile while you are at it. Update Here
Complete your profile to access more resources. Update Here

Key Reinstallation Attack (KRACK) Wi-Fi® Vulnerabilities

Overview


The Key Reinstallation Attack (KRACK) exploits weaknesses in Wi‑Fi Protected Access II (WPA2) key management. Under specific conditions, an attacker within radio range may be able to replay, decrypt or forge packets. Exploitation requires proximity and specific conditions and does not enable persistent device compromise. 

Mitigation depends on your system configuration. For Linux®-hosted systems, WPA2 key management can be implemented in wpa_supplicant, so mitigation requires updating wpa_supplicant. For other systems, WPA2 key management is implemented in device firmware, so mitigation requires updating the device firmware. Refer to the Affected Products and Resolution table for the firmware versions that include fixes for this vulnerability. 

Vulnerabilities Covered 


This page addresses the following KRACK‑related vulnerabilities identified by Common Vulnerabilities and Exposures (CVEs), which impact WPA2 implementations at the protocol and implementation level: 

  • CVE‑2017‑13077: Reinstallation of the Pairwise Encryption Key (PTK‑TK) in the 4-way handshake 

  • CVE‑2017‑13079: Reinstallation of the Integrity Group Key (IGTK) in the four-way handshake 

  • CVE‑2017‑13082: Accepting retransmitted fast Basic Service Set (BSS) transition reassociation requests and reinstalling the PTK-TK while processing it 

  • CVE‑2017‑13086: Reinstallation of the Tunneled Direct-Link Setup (TDLS) PeerKey (TPK) key in the TDLS handshake 

  • CVE-2017-13087: Reinstallation of the GTK when processing a Wireless Network Management (WNM) sleep mode response frame 

  • CVE‑2017‑13088: Reinstallation of the IGTK when processing a WNM sleep mode response frame 

Note: Not all KRACK CVEs apply to every device type. Applicability depends on supported protocol features, such as IGTK, and implementation details. 

Related Vulnerability


Some of our wireless products are also affected by a related vulnerability. This vulnerability allows non-Quality-of-Service (non-QoS) frames to bypass Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP) and Temporal Key Integrity Protocol (TKIP) replay detection if a Block Acknowledgement (Block Ack) session is active. It does not have a CVE assigned so it is listed as “CCMP/TKIP Replay” in the affected products table.

Affected Products and Resolution


Last Updated: June 30, 2026

Software/FirmwareAssociated HardwareCVE/VulnerabilityResolution / Mitigation
ATWILC1000/ATWILC3000 RTOS Driver Firmware

ATWILC1000, ATWILC1000-IC

ATWILC3000, ATWILC3000-IC

CVE-2017-13077

CVE-2017-13078

CVE-2017-13080

Update to version 4.2.1 or later

CCMP/TKIP Replay

No fix available
ATWINC1500 Firmware

ATSAMW25H18

ATWINC1500, ATWINC1500-IC 
ATWINC1510, ATWINC1510-IC

CVE-2017-13077

CVE-2017-13078

CVE-2017-13080

Update to version 19.5.4 or later
CCMP/TKIP ReplayUpdate to version 19.7.5 or later
ATWINC3400 FirmwareATWINC3400, ATWINC3400-IC

CVE-2017-13077

CVE-2017-13078

CVE-2017-13080

Update to version 1.2.2 or later
CCMP/TKIP ReplayUpdate to version 1.4.3 or later
MPLAB® Harmony v3 wireless_wifi RepositoryWFI32E04UC, WFI32E04UE, WFI32E03PC, WFI32E03UC, WFI32E03PE, WFI32E03UE, WFI32E02UC, WFI32E02UE, WFI32E01PC, WFI32E01UC, WFI32E01PE, WFI32E01UE, PIC32MZ2051W104132, PIC32MZ1025W104132 

CVE-2017-13079

CVE-2017-13081

No fix available
CCMP/TKIP ReplayUpdate to version 3.6.0 or later
RNWF02 FirmwareRNWF02PC, RNWF02UC, RNWF02PE, RNWF02UE

CVE-2017-13079

CVE-2017-13081

Update to version 3.1.0 or later
WINCS02 FirmwareWINCS02PC, WINCS02UC, WINCS02PE, WINCS02UE

CVE-2017-13079

CVE-2017-13081

Update to version 3.1.0 or later
MRF24WG0Mx Factory Firmware

MRF24WG0MA

MRF24WG0MB, MRF24WG0MBT 

 Order parts with updated firmware: 
MRF24WG0MA-I/RM110 
MRF24WG0MB-I/RM110 
MRF24WG0MBT-I/RM110
RN171/131 Firmware

RN171, RN171XV

RN131, RN131C

 Update to version 4.8.3 or later
RN1723 FirmwareRN1723 

 

 

Update to version 1.5.2 or later

 

 

RN1810 FirmwareRN1810, RN1810E No fix available; product is End of Life (EOL)

Products Not Listed


Only products listed in the Affected Products and Resolution section of this advisory are known to be affected by these vulnerabilities.

Reference Documentation


Reference documentation includes the following third-party materials:

Live Chat

Need Help?

Privacy Policy