¡¾Îó²îͨ¸æ¡¿À¶ÑÀ & WiFi оƬ12Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-12-14


0x00 Îó²î¸ÅÊö

2021Äê12ÔÂ13ÈÕ£¬£¬£¬£¬£¬ £¬£¬¶à¸öÑо¿»ú¹¹ÁªºÏÐû²¼ÁËÀ¶ÑÀ¼°WiFi¼Ü¹¹ºÍЭÒéÖеĶà¸öÇå¾²Îó²î£¬£¬£¬£¬£¬ £¬£¬ÕâЩÎó²îÓ°ÏìÁËÊýÊ®ÒÚWiFiºÍÀ¶ÑÀоƬ£¬£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÎó²îÕë¶Ô×°±¸µÄÀ¶ÑÀ×é¼þÌáÈ¡ÃÜÂë²¢¼à¿ØWiFiоƬÉϵÄÁ÷Á¿¡£¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

ÏÖ´úÏûºÄÀàµç×Ó×°±¸£¨ÈçÖÇÄÜÊÖ»ú£©µÄSoC¾ßÓÐ×ÔÁ¦µÄÀ¶ÑÀ¡¢WiFiºÍLTE×é¼þ£¬£¬£¬£¬£¬ £¬£¬Ã¿¸ö×é¼þ¶¼ÓÐ×Ô¼ºµÄרÓÃÇ徲ʵÏÖ£¬£¬£¬£¬£¬ £¬£¬µ«ÕâЩ×é¼þͨ³£¹²ÏíÏàͬµÄ×ÊÔ´£¬£¬£¬£¬£¬ £¬£¬¿ÉÒÔ½«ÕâЩ¹²Ïí×ÊÔ´ÓÃ×÷¿çÎÞÏßоƬ½çÏßÌᳫºáÏòȨÏÞÌáÉý¹¥»÷µÄÇÅÁº£¬£¬£¬£¬£¬ £¬£¬ÒÔʵÏÖ´úÂëÖ´ÐС¢ÄÚ´æ¶ÁÈ¡ºÍ¾Ü¾øÐ§À͵ȡ£¡£¡£¡£¡£¡£

image.png

ΪÁËʹÓÃÕâЩÎó²î£¬£¬£¬£¬£¬ £¬£¬Ê×ÏÈÐèÒªÔÚÀ¶ÑÀ»ò WiFi оƬÉÏÖ´ÐдúÂ룬£¬£¬£¬£¬ £¬£¬Ò»µ©ÊµÏÖ£¬£¬£¬£¬£¬ £¬£¬¾Í¿ÉÒÔʹÓù²ÏíÄÚ´æ×ÊÔ´¶Ô×°±¸µÄÆäËûоƬ¾ÙÐкáÏò¹¥»÷¡£¡£¡£¡£¡£¡£ÕâЩÎó²î°üÀ¨£º

l  CVE-2020-10368£ºWiFi δ¼ÓÃÜÊý¾Ýй¶£¨¼Ü¹¹£©

l  CVE-2020-10367£ºWi-Fi ´úÂëÖ´ÐУ¨¼Ü¹¹£©

l  CVE-2019-15063£ºWi-Fi ¾Ü¾øÐ§ÀÍ£¨Ð­Ò飩

l  CVE-2020-10370£ºÀ¶ÑÀ¾Ü¾øÐ§ÀÍ£¨Ð­Ò飩

l  CVE-2020-10369£ºÀ¶ÑÀÊý¾Ýй¶£¨Ð­Ò飩

l  CVE-2020-29531£ºWiFi ¾Ü¾øÐ§ÀÍ£¨Ð­Ò飩

l  CVE-2020-29533£ºWiFi Êý¾Ý×ß©£¨Ð­Ò飩

l  CVE-2020-29532£ºÀ¶ÑÀ¾Ü¾øÐ§ÀÍ£¨Ð­Ò飩

l  CVE-2020-29530£ºÀ¶ÑÀÊý¾Ýй¶£¨Ð­Ò飩

ÕâЩÎó²î±£´æÓÚBroadcom¡¢Silicon Labs ºÍ Cypress µÈÖÆÔìÉÌÉú²úµÄоƬÖУ¬£¬£¬£¬£¬ £¬£¬¶øÕâЩоƬӦÓÃÓÚÊýÊ®ÒÚµç×Ó×°±¸ÖС£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Õë¶Ô CVE-2020-10368 ºÍ CVE-2020-10367 ²âÊÔµÄ×°±¸ÈçÏ£º

image.png

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÔÝδÍêÈ«ÐÞ¸´¡£¡£¡£¡£¡£¡£½¨ÒéʹÓÃÈçϱ£»£»£»£»£»£»¤²½·¥£º

l  ɾ³ý²»ÐëÒªµÄÀ¶ÑÀ×°±¸Åä¶Ô£»£»£»£»£»£»

l  ´ÓÉèÖÃÖÐɾ³ý²»Ê¹ÓÃµÄ WiFi ÍøÂ磻£»£»£»£»£»

l  ÔÚ¹«¹²³¡ºÏʹÓÃÊÖʱ»ú¼û»¥ÁªÍø¶ø²»ÊÇ WiFi¡£¡£¡£¡£¡£¡£

²Î¿¼Á´½Ó£º

https://arxiv.org/pdf/2112.05719.pdf

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/security/bugs-in-billions-of-wifi-bluetooth-chips-allow-password-data-theft/

https://securityaffairs.co/wordpress/125585/hacking/wifi-chip-coexistence-attacks.html?utm_source=rss&utm_medium=rss&utm_campaign=wifi-chip-coexistence-attacks

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-12-14

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¿­Ê±K66¼ò½é

¿­Ê±K66¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬ £¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬£¬ £¬£¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬£¬ £¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬£¬£¬£¬£¬ £¬£¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬£¬£¬£¬£¬ £¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£¡£

¶àÄêÀ´£¬£¬£¬£¬£¬ £¬£¬¿­Ê±K66ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬ £¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬ £¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£


¹ØÓÚ¿­Ê±K66

¿­Ê±K66Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬ £¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png