¡¾Îó²îͨ¸æ¡¿À¶ÑÀ & WiFi оƬ12Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-12-140x00 Îó²î¸ÅÊö
2021Äê12ÔÂ13ÈÕ£¬¶à¸öÑо¿»ú¹¹ÍŽáÐû²¼ÁËÀ¶ÑÀ¼°WiFi¼Ü¹¹ºÍÐÒéÖеĶà¸öÇå¾²Îó²î£¬ÕâЩÎó²îÓ°ÏìÁËÊýÊ®ÒÚWiFiºÍÀ¶ÑÀоƬ£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÎó²îÕë¶Ô×°±¸µÄÀ¶ÑÀ×é¼þÌáÈ¡ÃÜÂë²¢¼à¿ØWiFiоƬÉϵÄÁ÷Á¿¡£
0x01 Îó²îÏêÇé

ÏÖ´úÏûºÄÀàµç×Ó×°±¸£¨ÈçÖÇÄÜÊÖ»ú£©µÄSoC¾ßÓÐ×ÔÁ¦µÄÀ¶ÑÀ¡¢WiFiºÍLTE×é¼þ£¬Ã¿¸ö×é¼þ¶¼ÓÐ×Ô¼ºµÄרÓÃÇ徲ʵÏÖ£¬µ«ÕâЩ×é¼þͨ³£¹²ÏíÏàͬµÄ×ÊÔ´£¬¿ÉÒÔ½«ÕâЩ¹²Ïí×ÊÔ´ÓÃ×÷¿çÎÞÏßоƬ½çÏßÌᳫºáÏòȨÏÞÌáÉý¹¥»÷µÄÇÅÁº£¬ÒÔʵÏÖ´úÂëÖ´ÐС¢ÄÚ´æ¶ÁÈ¡ºÍ¾Ü¾ø·þÎñµÈ¡£

ΪÁËʹÓÃÕâЩÎó²î£¬Ê×ÏÈÐèÒªÔÚÀ¶ÑÀ»ò WiFi оƬÉÏÖ´ÐдúÂ룬һµ©ÊµÏÖ£¬¾Í¿ÉÒÔʹÓù²ÏíÄÚ´æ×ÊÔ´¶Ô×°±¸µÄÆäËûоƬ¾ÙÐкáÏò¹¥»÷¡£ÕâЩÎó²î°üÀ¨£º
l CVE-2020-10368£ºWiFi δ¼ÓÃÜÊý¾Ýй¶£¨¼Ü¹¹£©
l CVE-2020-10367£ºWi-Fi ´úÂëÖ´ÐУ¨¼Ü¹¹£©
l CVE-2019-15063£ºWi-Fi ¾Ü¾ø·þÎñ£¨ÐÒ飩
l CVE-2020-10370£ºÀ¶ÑÀ¾Ü¾ø·þÎñ£¨ÐÒ飩
l CVE-2020-10369£ºÀ¶ÑÀÊý¾Ýй¶£¨ÐÒ飩
l CVE-2020-29531£ºWiFi ¾Ü¾ø·þÎñ£¨ÐÒ飩
l CVE-2020-29533£ºWiFi Êý¾Ý×ß©£¨ÐÒ飩
l CVE-2020-29532£ºÀ¶ÑÀ¾Ü¾ø·þÎñ£¨ÐÒ飩
l CVE-2020-29530£ºÀ¶ÑÀÊý¾Ýй¶£¨ÐÒ飩
ÕâЩÎó²î±£´æÓÚBroadcom¡¢Silicon Labs ºÍ Cypress µÈÖÆÔìÉÌÉú²úµÄоƬÖУ¬¶øÕâЩоƬӦÓÃÓÚÊýÊ®ÒÚµç×Ó×°±¸ÖС£Ñо¿Ö°Ô±Õë¶Ô CVE-2020-10368 ºÍ CVE-2020-10367 ²âÊÔµÄ×°±¸ÈçÏ£º

0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÔÝδÍêÈ«ÐÞ¸´¡£½¨ÒéʹÓÃÈçϱ£»¤²½·¥£º
l ɾ³ý²»ÐëÒªµÄÀ¶ÑÀ×°±¸Åä¶Ô£»
l ´ÓÉèÖÃÖÐɾ³ý²»Ê¹ÓÃµÄ WiFi ÍøÂ磻
l ÔÚ¹«¹²³¡ºÏʹÓÃÊÖʱ»ú¼û»¥ÁªÍø¶ø²»ÊÇ WiFi¡£
²Î¿¼Á´½Ó£º
https://arxiv.org/pdf/2112.05719.pdf
0x03 ²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/bugs-in-billions-of-wifi-bluetooth-chips-allow-password-data-theft/
https://securityaffairs.co/wordpress/125585/hacking/wifi-chip-coexistence-attacks.html?utm_source=rss&utm_medium=rss&utm_campaign=wifi-chip-coexistence-attacks
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-12-14 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
×ðÁú¿Ê±¼ò½é
×ðÁú¿Ê±¹«Ë¾½¨ÉèÓÚ1996Ä꣬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Çå¾²·þÎñÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£
¶àÄêÀ´£¬×ðÁú¿Ê±ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£
¹ØÓÚ×ðÁú¿Ê±
×ðÁú¿Ê±Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£
¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ