KNOB (Key Negotiation of Bluetooth) is a weakness in the Bluetooth BR/EDR Core Specification through version 5.1. The specification permits negotiation of insufficiently short encryption keys and does not adequately authenticate or protect key-length negotiation from manipulation. An unauthenticated adjacent attacker can inject packets during connection establishment or encryption renegotiation to force the peers to use a low-entropy session key. The resulting key can be practically brute-forced, allowing the attacker to decrypt protected Bluetooth traffic and inject ciphertext without detection.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides a comprehensive toolkit and documentation for performing the KNOB (Key Negotiation of Bluetooth) attack (CVE-2019-9506) against Bluetooth BR/EDR and BLE devices. The structure is as follows: - The `e0/` directory contains Python scripts and modules for brute-forcing and validating low-entropy E0 encryption keys, including implementations of Bluetooth cryptographic primitives (E0 stream cipher, hash functions, entropy reduction) and test cases. The main brute-force script is `e0/bf.py`. - The `poc-internalblue/` directory contains a proof-of-concept implementation using the InternalBlue framework, which allows patching and monitoring of the Broadcom Bluetooth controller firmware (specifically for Nexus 5 devices). It includes scripts to patch the firmware, monitor LMP (Link Manager Protocol) traffic, and perform the attack in practice. The main exploit scripts are in `poc-internalblue/internalblue/examples/`. - The `ble/` directory provides instructions for patching the Linux kernel to manipulate BLE key entropy, enabling testing of BLE devices' susceptibility to the attack. - The `wireshark/` directory contains Wireshark plugins and coloring rules to facilitate analysis of Bluetooth LMP traffic during attacks. The exploit's main capability is to force the negotiation of Bluetooth encryption keys with minimal entropy (as low as 1 byte), making brute-force attacks practical. The InternalBlue-based PoC demonstrates how to patch the controller firmware to manipulate key negotiation and monitor traffic, while the E0 scripts automate the brute-forcing of weak keys. The repository targets a wide range of Bluetooth devices that have not been patched against CVE-2019-9506, and provides tools for both attack and analysis. No hardcoded network endpoints are present, but several file paths and device addresses are used for local configuration and operation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
KNOB Bluetooth BR/EDR encryption-key negotiation vulnerability.
Bluetooth BR/EDR encryption-key negotiation vulnerability known as KNOB.
The KNOB vulnerability: a Bluetooth BR/EDR encryption-key negotiation weakness that can permit attacks against negotiated encryption strength.
The KNOB vulnerability affecting Bluetooth BR/EDR encryption-key negotiation.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.