C
æå
ã«
Kaspersky ICS CERTãQualcomm Snapdragonãããã»ããã®BootROMã«è匱æ§ãçºèŠããŸãã
ð äžèšã§ãããš
Kaspersky ICS CERTãQualcomm Snapdragonãããã»ããã®BootROMã«è匱æ§ãçºèŠããŸããããã®è匱æ§ã¯ã¹ããŒããã©ã³ãã¿ãã¬ãããè»èŒæ©åšãIoTããã€ã¹ãªã©ãåºç¯å²ãªããã€ã¹ã«åœ±é¿ãäžããŸããæ»æã®å®è¡ã«ã¯ç©ççãªã¢ã¯ã»ã¹ãå¿
èŠã§ãããå
Œ
±ã®USBå
é»ããŒããªã©ãä»ããŠæªçšããããªã¹ã¯ãææãããŠããŸããå
·äœçã«ã¯ãç·æ¥ããŠã³ããŒãïŒEDLïŒã¢ãŒãã§äœ¿çšãããQualcomm Saharaãããã³ã«ã®äžåãåå ã§ãã
ð¢åœ±é¿ç¯å²
Snapdragonãããã»ãããæèŒããã¹ããŒããã©ã³ãã¿ãã¬ãããè»èŒã·ã¹ãã ãIoTããã€ã¹ãå©çšããå
šäžçã®ãŠãŒã¶ãŒããã³çµç¹ã
â
è©²åœæã®å¯Ÿå¿
空枯ãããã«ãªã©ã®å
Œ
±ã®å Žæã«ããä¿¡é Œã§ããªãUSBå
é»ã¹ããŒã·ã§ã³ãããŒããžã®æ¥ç¶ãé¿ããããšãããã€ã¹ã®ç©ççãªç®¡çã培åºããäžæ£ãªã¢ã¯ã»ã¹ã鲿¢ããããšã
ð§ ã¡ãŒã«æ¡ãèŠã (瀟å¡åã + 管çè åã)
â ïž ãã㯠AI ãçæããåèäŸã§ããé
ä¿¡åã«å¿
ãå
容ãã確èªã®ããã貎瀟ã®ç¶æ³ã«åãããŠç·šéããŠãå©çšãã ãããå®éã®è¢«å®³ç¶æ³ãèªç€Ÿã®å©çšç°å¢ãèžãŸãã倿ã¯ã貎瀟ã®ã»ãã¥ãªãã£è²¬ä»»è
ã«ã確èªãã ããã
ä»¶å: ãæ³šæåèµ·ãå
Œ
±ã®USBå
é»ããŒãå©çšã«é¢ãããæ³šæ
ãç²ãããŸã§ããæ å ±ã·ã¹ãã æ åœã§ãã
Qualcomm瀟ã®Snapdragonãããã»ãããæèŒããããã€ã¹ïŒã¹ããŒããã©ã³ãã¿ãã¬ããçïŒã«ãããŠãç©ççãªæ¥ç¶ãä»ããŠæ»æãåããå¯èœæ§ãããè匱æ§ãå ±åãããŸããã
ãååããé¡ããããããš:
1. 空枯ãããã«ãªã©ã®å ¬å ±ã®å Žæã«ãããä¿¡é Œã§ããªãUSBå é»ã¹ããŒã·ã§ã³ãããŒããžã®æ¥ç¶ãé¿ããŠãã ããã
2. èªèº«ã®ããã€ã¹ã第äžè ã«é ããããæŸçœ®ãããããªãããç©ççãªç®¡çã培åºããŠãã ããã
ã»ãã¥ãªãã£ç¶æã®ããããæ©ãã«ãçæããã ããŸããããé¡ãããããŸãã
ãç²ãããŸã§ããæ å ±ã·ã¹ãã æ åœã§ãã
Qualcomm瀟ã®Snapdragonãããã»ãããæèŒããããã€ã¹ïŒã¹ããŒããã©ã³ãã¿ãã¬ããçïŒã«ãããŠãç©ççãªæ¥ç¶ãä»ããŠæ»æãåããå¯èœæ§ãããè匱æ§ãå ±åãããŸããã
ãååããé¡ããããããš:
1. 空枯ãããã«ãªã©ã®å ¬å ±ã®å Žæã«ãããä¿¡é Œã§ããªãUSBå é»ã¹ããŒã·ã§ã³ãããŒããžã®æ¥ç¶ãé¿ããŠãã ããã
2. èªèº«ã®ããã€ã¹ã第äžè ã«é ããããæŸçœ®ãããããªãããç©ççãªç®¡çã培åºããŠãã ããã
ã»ãã¥ãªãã£ç¶æã®ããããæ©ãã«ãçæããã ããŸããããé¡ãããããŸãã
Subject: [Security Notice] Caution Regarding Public USB Charging Ports
Hi everyone,
A vulnerability has been reported in devices using Qualcomm Snapdragon chipsets (such as smartphones and tablets) that could allow an attacker to compromise the device via a physical connection.
Requested Actions:
1. Avoid using untrusted USB charging stations or ports in public areas, such as airports or hotels.
2. Ensure your devices are physically secure and never left unattended or handed over to unauthorized individuals.
Please keep these precautions in mind for your security.
Hi everyone,
A vulnerability has been reported in devices using Qualcomm Snapdragon chipsets (such as smartphones and tablets) that could allow an attacker to compromise the device via a physical connection.
Requested Actions:
1. Avoid using untrusted USB charging stations or ports in public areas, such as airports or hotels.
2. Ensure your devices are physically secure and never left unattended or handed over to unauthorized individuals.
Please keep these precautions in mind for your security.
ä»¶å: ãå
±æãQualcomm Snapdragon BootROMã®è匱æ§ã«ã€ããŠ
ãç²ãããŸã§ããSnapdragonãããã»ããã®è匱æ§ã«é¢ããæ å ±å ±æã§ãã
â æŠèŠ
Kaspersky ICS CERTã«ãããQualcomm Snapdragonã®BootROMïŒããŒããŠã§ã¢ã¬ãã«ã®ããŒãããã»ããµïŒã«è匱æ§ãçºèŠãããŸãããQualcomm Saharaãããã³ã«ã®äžåã«ãããç·æ¥ããŠã³ããŒãïŒEDLïŒã¢ãŒããä»ããŠãç©ççã«æ¥ç¶ãããæ»æè ãããã€ã¹ãæäœã§ããå¯èœæ§ããããŸãã
â 圱é¿ç¯å²
- Snapdragonãããã»ãããæèŒããã¹ããŒããã©ã³ãã¿ãã¬ãããè»èŒæ©åšãIoTããã€ã¹
â å¯Ÿå¿æé
1. ãŠãŒã¶ãŒã«å¯Ÿããå ¬å ±ã®USBå é»ããŒãïŒãžã¥ãŒã¹ãžã£ããã³ã°çã®ãªã¹ã¯ïŒã®å©çšçŠæ¢ãåšç¥ããŠãã ããã
2. ç©ççãªããã€ã¹ç®¡çïŒçŽå€±ã»çé£é²æ¢ïŒã®åŸ¹åºãæç€ºããŠãã ããã
3. æ¬è匱æ§ã¯BootROMã«ååšãããããããŒããŠã§ã¢ã¬ãã«ã®ä¿®æ£ãå°é£ãªå ŽåããããŸãããã³ããŒããã®ä»åŸã®ã¢ããããŒãæ å ±ãç¶ç¶çã«ç£èŠããŠãã ããã
â åèæ å ±
- Kaspersky ICS CERT / xakep
察å¿åªå 床: é«ïŒç©çã¢ã¯ã»ã¹ã䌎ããªã¹ã¯ããããããéãããªæ³šæåèµ·ãæšå¥šïŒ
ãç²ãããŸã§ããSnapdragonãããã»ããã®è匱æ§ã«é¢ããæ å ±å ±æã§ãã
â æŠèŠ
Kaspersky ICS CERTã«ãããQualcomm Snapdragonã®BootROMïŒããŒããŠã§ã¢ã¬ãã«ã®ããŒãããã»ããµïŒã«è匱æ§ãçºèŠãããŸãããQualcomm Saharaãããã³ã«ã®äžåã«ãããç·æ¥ããŠã³ããŒãïŒEDLïŒã¢ãŒããä»ããŠãç©ççã«æ¥ç¶ãããæ»æè ãããã€ã¹ãæäœã§ããå¯èœæ§ããããŸãã
â 圱é¿ç¯å²
- Snapdragonãããã»ãããæèŒããã¹ããŒããã©ã³ãã¿ãã¬ãããè»èŒæ©åšãIoTããã€ã¹
â å¯Ÿå¿æé
1. ãŠãŒã¶ãŒã«å¯Ÿããå ¬å ±ã®USBå é»ããŒãïŒãžã¥ãŒã¹ãžã£ããã³ã°çã®ãªã¹ã¯ïŒã®å©çšçŠæ¢ãåšç¥ããŠãã ããã
2. ç©ççãªããã€ã¹ç®¡çïŒçŽå€±ã»çé£é²æ¢ïŒã®åŸ¹åºãæç€ºããŠãã ããã
3. æ¬è匱æ§ã¯BootROMã«ååšãããããããŒããŠã§ã¢ã¬ãã«ã®ä¿®æ£ãå°é£ãªå ŽåããããŸãããã³ããŒããã®ä»åŸã®ã¢ããããŒãæ å ±ãç¶ç¶çã«ç£èŠããŠãã ããã
â åèæ å ±
- Kaspersky ICS CERT / xakep
察å¿åªå 床: é«ïŒç©çã¢ã¯ã»ã¹ã䌎ããªã¹ã¯ããããããéãããªæ³šæåèµ·ãæšå¥šïŒ
Subject: [Security Advisory] Vulnerability in Qualcomm Snapdragon BootROM
Hi,
This is a security notification regarding a vulnerability discovered in Qualcomm Snapdragon chipsets.
â Overview
Kaspersky ICS CERT has identified a vulnerability in the BootROM of Qualcomm Snapdragon chipsets. Due to a flaw in the Qualcomm Sahara protocol used in Emergency Download (EDL) mode, an attacker with physical access to the device can potentially compromise it via a cable connection.
â Scope
- Devices equipped with Snapdragon chipsets, including smartphones, tablets, automotive components, and IoT devices.
â Recommended Actions
1. Advise users to avoid using untrusted public USB charging stations (mitigating juice-jacking risks).
2. Enforce strict physical device management policies to prevent unauthorized access.
3. Since this is a BootROM vulnerability, hardware-level patching may be limited. Please monitor vendor advisories for any available firmware mitigations.
â Reference
- Kaspersky ICS CERT / xakep
Priority: High (Prompt notification to users is recommended due to the nature of the physical attack vector).
Hi,
This is a security notification regarding a vulnerability discovered in Qualcomm Snapdragon chipsets.
â Overview
Kaspersky ICS CERT has identified a vulnerability in the BootROM of Qualcomm Snapdragon chipsets. Due to a flaw in the Qualcomm Sahara protocol used in Emergency Download (EDL) mode, an attacker with physical access to the device can potentially compromise it via a cable connection.
â Scope
- Devices equipped with Snapdragon chipsets, including smartphones, tablets, automotive components, and IoT devices.
â Recommended Actions
1. Advise users to avoid using untrusted public USB charging stations (mitigating juice-jacking risks).
2. Enforce strict physical device management policies to prevent unauthorized access.
3. Since this is a BootROM vulnerability, hardware-level patching may be limited. Please monitor vendor advisories for any available firmware mitigations.
â Reference
- Kaspersky ICS CERT / xakep
Priority: High (Prompt notification to users is recommended due to the nature of the physical attack vector).