漏洞信息详情
多款Qualcomm产品加密问题漏洞
漏洞简介
Qualcomm MSM8996AU等都是美国高通(Qualcomm)公司的产品。MSM8996AU是一款中央处理器(CPU)产品。SDX20是一款调制解调器。APQ8053是一款中央处理器(CPU)产品。
多款Qualcomm产品中的WIFI driver(Krook)存在加密问题漏洞。该漏洞源于网络系统或产品未正确使用相关密码算法,导致内容未正确加密、弱加密、明文存储敏感信息等。以下产品及版本受到影响:Qualcomm APQ8053;IPQ4019;IPQ8064;MSM8909W;MSM8996AU;QCA9531;QCN5502;QCS405;SDX20;SM6150;SM7150。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.qualcomm.com/company/product-security/bulletins/august-2020-security-bulletin
参考网址
来源:CONFIRM
链接:https://www.arista.com/en/support/advisories-notices/security-advisories/11998-security-advisory-58
来源:CONFIRM
链接:https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletin
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-4978
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Qualcomm-Atheros-IEEE-802-11n-no-chiffrement-36534
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164584/Ubuntu-Security-Notice-USN-5115-1.html
来源:www.qualcomm.com
链接:https://www.qualcomm.com/company/product-security/bulletins/august-2020-security-bulletin
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3535
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164594/Ubuntu-Security-Notice-USN-5116-2.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3483
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3512
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-3702
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3225
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3422
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3455
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164561/Ubuntu-Security-Notice-USN-5113-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3391
受影响实体
暂无
补丁
- 多款Qualcomm产品加密问题漏洞的修复措施<!--2020-8-3-->
还没有评论,来说两句吧...