[ad_1]
Cui You Spent 10 years Invade Office phones and other “embedded devices” connected to the Internet—that is, not Look Like a computer or server, but with all the characteristics: processor, memory, and usually the ability to connect to other devices or the Internet. As the founder of Red Balloon Security, Cui spent a lot of time evaluating complex industrial control systems and even satellite infrastructure, but he still returned to IP telephony as a barometer of the progress of IoT security. His latest research shows that there is still a long way to go.
At the SummerCon security conference in New York City on Friday, Cui and his Red Balloon colleague Yuanzhe Wu presented a new discovery about a vulnerability. More than ten models Cisco IP desk phone. It can only be exploited through physical access to the target device, but if an attacker manages to do this, they can gain complete control of the phone, and then they can use it to eavesdrop on the phone, eavesdrop on the surrounding room, or perform other malicious actions. activity.
A Cisco spokesperson told Wired in a statement that “Cisco has issued a software update for this issue and is not aware that the vulnerability described in the announcement has been used maliciously.” He was referring to Security notice The company released it on Wednesday.
However, Red Balloon researchers said that Cisco’s patch did not completely eliminate this vulnerability. It only makes vulnerabilities more difficult to exploit. This is because the vulnerabilities they found do not actually exist in the code that Cisco can rewrite or control. Instead, it resides in low-level firmware developed by chip manufacturer Broadcom for the processor Cisco uses as an additional hardware security feature. This also means that the same vulnerabilities may exist in other embedded devices using the same Broadcom chip.
Broadcom did not respond to WIRED’s multiple requests for comment, but Cisco said on Wednesday that the flaw exists in Broadcom’s firmware implementation.
“Look, we were here before. I disclosed the IP phone vulnerabilities to Cisco. They have made great progress in many ways,” Cui told WIRED before SummerCon. “But the fact that there are loopholes here is not surprising. In the end, these things are not more secure than they were 10 years ago.”
Red Balloon Security researchers tested the vulnerability on the Cisco 8841 phone, which contains the Broadcom BCM 911360 TrustZone chip, which is specifically designed to provide a hardware “root of trust” for the phone.hardware The root of trust Can strengthen the overall safety of the equipment.For example, Microsoft is currently Big push For users to adopt them as part of the Windows 11 system requirements. The idea is to add an additional chip to run code that is immutable and cannot be fundamentally changed by the main processor of the device. In this way, TrustZone can be trusted to essentially observe the rest of the system and implement security protections, such as initiating monitoring, without risking its own damage.
Hardware roots of trust can improve the security of devices, but in practice, they can also cause the problem of “who is monitoring the observer”. If there are loopholes in the hardware security features, they will silently destroy the integrity of the entire device.
The Broadcom chip that the researchers studied in Cisco mobile phones has an application programming interface that allows for limited interactions such as setting up device encryption services. However, the researchers found a flaw in the API that could allow an attacker to trick it into executing commands that should not be allowed to be accepted.
[ad_2]
Source link






