CVE-2017-13077 is the KRACK variant affecting WPA/WPA2 unicast Pairwise Transient Key (PTK) handling during the 4-way handshake. A logic flaw in state transition handling allows retransmitted/replayed handshake messages to trigger reinstallation of an already-in-use PTK/Temporal Key (TK). This causes nonce/packet number reuse on the client side. The issue is described by vendors and upstream maintainers as reinstallation of the pairwise key in the four-way handshake, and upstream wpa_supplicant/hostapd fixes refer to preventing WPA packet number reuse with replayed messages and key reinstallation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a containerized WPA2/KRACK lab rather than a standalone remote exploit against an Internet-facing service. Its purpose is to reproduce and study the WPA2 4-way handshake and demonstrate KRACK (CVE-2017-13077) behavior in an isolated Linux environment using mac80211_hwsim virtual radios, Dockerized hostapd/wpa_supplicant, packet capture, and an offline Python verifier. Structure: the ap/ directory builds an Ubuntu-based hostapd container with hostapd.conf and start_ap.sh; the client/ directory builds a wpa_supplicant container with its own config and launcher; docker-compose.yml runs both with host networking and NET_ADMIN/SYS_RAWIO. The scripts/ directory contains the operational logic: setup_interfaces.sh reloads mac80211_hwsim and prepares wlan0/wlan1/wlan2/hwsim0; run_handshake.sh captures EAPOL on hwsim0 and launches the AP/client containers; analyzer.py parses the resulting PCAP, extracts EAPOL frames and MACs, derives PMK/PTK/KCK/KEK/TK from hardcoded SSID/password, and verifies MICs for messages 2-4; run_krack_demo.sh orchestrates a KRACK replay demo using an external checkout of vanhoefm/krackattacks-scripts. Main exploit capabilities: (1) establish a WPA2-PSK AP/client handshake over virtual radios; (2) capture handshake traffic to PCAP; (3) cryptographically validate the handshake offline; (4) launch a KRACK test environment where message 3 is replayed repeatedly to a victim client and traffic is captured on wlan2. The actual KRACK replay logic is not implemented in this repository itself; it delegates to the external krack-test-client.py from krackattacks-scripts. Therefore this repo is best characterized as an operational lab/orchestrator for exploit reproduction and verification. Targeting: the documented vulnerability is CVE-2017-13077, affecting WPA2 clients vulnerable to pairwise key reinstallation. The repo explicitly notes patched behavior in modern wpa_supplicant (2.7+ / 2.10) and vulnerable behavior in older clients. The attack vector is primarily wireless/network, but execution is local because the operator must control the host running the virtual radios and containers. Notable observables include SSIDs LabNet_01 and testnetwork, interfaces wlan0/wlan1/wlan2/hwsim0, capture files shared/capture.pcap and shared/krack_capture.pcap, temporary config /tmp/krack_client.conf, and external dependency path ~/krackattacks/krackattack. Hardcoded credentials are present for the lab environment, enabling deterministic PMK/PTK derivation and handshake verification.
This repository is a containerized WPA2/KRACK lab rather than a standalone remote exploit against arbitrary hosts. It contains two Dockerized roles—an AP using hostapd and a client using wpa_supplicant—plus orchestration scripts to create virtual Wi‑Fi radios with mac80211_hwsim, capture the WPA2 4-way handshake, and optionally run a KRACK replay demonstration using an external dependency (Mathy Vanhoef's krackattacks-scripts). The main exploit capability is in scripts/run_krack_demo.sh, which automates a local wireless attack scenario for CVE-2017-13077 by starting a victim AP container, capturing on wlan2, launching krack-test-client.py from ~/krackattacks/krackattack, generating /tmp/krack_client.conf for a victim client, and connecting wlan1 to the rogue AP to observe repeated MSG3 replays. The repository also includes scripts/run_handshake.sh for benign handshake capture and scripts/analyzer.py, a Python tool that reads shared/capture.pcap, extracts EAPOL frames, derives PMK/PTK/KCK/KEK/TK from hardcoded SSID LabNet_01 and passphrase LabPassphrase2024!, and verifies MICs for MSG2/MSG3/MSG4. Structure-wise, ap/ and client/ hold Dockerfiles and configs, scripts/ contains the operational logic, docs/ provides reproduction and KRACK notes, and shared/ stores generated pcaps/logs. No C2 or external victim endpoints are embedded beyond local interfaces, file paths, and the external GitHub dependency; the attack surface is wireless/local lab infrastructure using wlan0/wlan1/wlan2/hwsim0.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A KRACK-related Wi-Fi vulnerability involving forced nonce reuse in WPA unicast/PTK clients due to improper state transition handling. The content states no Apple Watch models were impacted by this vulnerability.
A KRACK-related Wi-Fi vulnerability allowing an attacker in Wi-Fi range to force nonce reuse in WPA unicast/PTK clients.
A KRACK-related Wi‑Fi logic flaw that may allow an attacker in Wi‑Fi range to force nonce reuse in WPA unicast/PTK clients.
One of the CVEs assigned to the KRACK (WPA2 key reinstallation) handshake vulnerabilities.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.