I am having this issue on an mk7 with tcpdump captured wpa2-psk-ccmp encrypted frames:

My Wireshark is only able to decrypt L3-L7 for some multicast and broadcast data frames, but not unicast data frames.

(When loading other .pcap decryptable example files on the Internet, Wireshark is correctly decrypting all unicast data frames.)

The captured EAPOL handshake #3 seems to be correctly decrypted, showing everything in clear: GTK, KEK, KCK. 

Anyone else ran into this issue?




