{"id":36876,"date":"2019-10-31T22:14:26","date_gmt":"2019-10-31T19:14:26","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi\/"},"modified":"2019-10-31T22:14:26","modified_gmt":"2019-10-31T19:14:26","slug":"uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi","title":{"rendered":"Una vulnerabilidad en los chips de Qualcomm permite atacar dispositivos Android a trav\u00e9s de Wi-Fi","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>En el stack inal\u00e1mbrico de chips Qualcomm <noindex><a rel=\"nofollow\" href=\"https:\/\/blade.tencent.com\/en\/advisories\/qualpwn\/\">se han identificado<\/a><\/noindex> tres vulnerabilidades que se presentan bajo el nombre en clave \u00abQualPwn\u00bb. El primer problema (CVE-2019-10539) permite atacar dispositivos basados en la plataforma Android de forma remota a trav\u00e9s de Wi-Fi. El segundo problema se encuentra en el firmware propietario con la pila inal\u00e1mbrica de Qualcomm y permite acceder al m\u00f3dem baseband (CVE-2019-10540). El tercer problema <noindex><a rel=\"nofollow\" href=\"https:\/\/source.codeaurora.org\/quic\/la\/kernel\/msm-4.9\/commit\/?id=e0d510ff0fcb0778571579635b53ddd7e4caeb24\">hay<\/a><\/noindex> est\u00e1 en el controlador icnss (CVE-2019-10538) y permite ejecutar c\u00f3digo en el nivel del n\u00facleo de la plataforma Android. En caso de que se exploten con \u00e9xito las vulnerabilidades mencionadas, el atacante puede controlar remotamente el dispositivo del usuario en el que Wi-Fi est\u00e1 activo (para el ataque, se requiere que la v\u00edctima y el atacante est\u00e9n conectados a la misma red inal\u00e1mbrica).<\/p>\n<p>La posibilidad de ataque ha sido demostrada para los smartphones Google Pixel 2 y Pixel 3. Seg\u00fan los investigadores, el problema potencialmente afecta a m\u00e1s de 835,000 dispositivos basados en SoC Qualcomm Snapdragon 835 y chips m\u00e1s nuevos (a partir de Snapdragon 835, el firmware WLAN fue integrado con el subsistema del m\u00f3dem y funcionaba como una aplicaci\u00f3n aislada en el espacio del usuario). Por <noindex><a rel=\"nofollow\" href=\"https:\/\/www.qualcomm.com\/company\/product-security\/bulletins\">los datos<\/a><\/noindex> Qualcomm, el problema afecta a varias docenas de chips diferentes. <\/p>\n<p>En la actualidad, solo hay informaci\u00f3n general sobre las vulnerabilidades, y los detalles <noindex><a rel=\"nofollow\" href=\"https:\/\/www.blackhat.com\/us-19\/briefings\/schedule\/index.html#exploiting-qualcomm-wlan-and-modem-over-the-air-15481\">est\u00e1 previsto<\/a><\/noindex> se revelar\u00e1n el 8 de agosto en la conferencia Black Hat. Las empresas Qualcomm y Google fueron notificadas sobre los problemas en marzo y ya han emitido correcciones (Qualcomm inform\u00f3 sobre los inconvenientes en el <noindex><a rel=\"nofollow\" href=\"https:\/\/www.qualcomm.com\/company\/product-security\/bulletins\">informe de junio<\/a><\/noindex>, mientras que Google abord\u00f3 las vulnerabilidades en el <noindex><a rel=\"nofollow\" href=\"https:\/\/source.android.com\/security\/bulletin\/2019-08-01.html\">actualizaci\u00f3n de agosto<\/a><\/noindex> de la plataforma Android). Se recomienda a todos los usuarios de dispositivos con chips Qualcomm que instalen las actualizaciones disponibles.<\/p>\n<p>Adem\u00e1s de los problemas relacionados con los chips Qualcomm, la actualizaci\u00f3n de agosto de la plataforma Android tambi\u00e9n resolvi\u00f3 una vulnerabilidad cr\u00edtica (CVE-2019-11516) en el stack Bluetooth de Broadcom, que permite al atacante ejecutar su c\u00f3digo en el contexto de un proceso privilegiado mediante el env\u00edo de una solicitud de transmisi\u00f3n de datos especialmente dise\u00f1ada. Tambi\u00e9n se ha solucionado una vulnerabilidad en los componentes del sistema de Android (CVE-2019-2130), que permite ejecutar c\u00f3digo con privilegios elevados al procesar archivos PAC especialmente creados.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51228\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u043c \u0441\u0442\u0435\u043a\u0435 \u0447\u0438\u043f\u043e\u0432 Qualcomm \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0440\u0435\u043f\u043e\u0434\u043d\u0435\u0441\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c &#171;QualPwn&#187;. \u041f\u0435\u0440\u0432\u0430\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 (CVE-2019-10539) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u0442\u044c \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430 \u043d\u0430 \u0431\u0430\u0437\u0435 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android \u0447\u0435\u0440\u0435\u0437 Wi-Fi. \u0412\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0432 \u043f\u0440\u043e\u043f\u0440\u0438\u0435\u0442\u0430\u0440\u043d\u043e\u0439 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0435 \u0441 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u043c \u0441\u0442\u0435\u043a\u043e\u043c Qualcomm \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a baseband-\u043c\u043e\u0434\u0435\u043c\u0443 (CVE-2019-10540). \u0422\u0440\u0435\u0442\u044c\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0432 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0435 icnss (CVE-2019-10538) \u0438 \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-36876","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u043c \u0441\u0442\u0435\u043a\u0435 \u0447\u0438\u043f\u043e\u0432 Qualcomm \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0440\u0435\u043f\u043e\u0434\u043d\u0435\u0441\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c &quot;QualPwn&quot;.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0447\u0438\u043f\u0430\u0445 Qualcomm, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u0442\u044c Android-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u043e \u0447\u0435\u0440\u0435\u0437 Wi-Fi | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u043c \u0441\u0442\u0435\u043a\u0435 \u0447\u0438\u043f\u043e\u0432 Qualcomm \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0440\u0435\u043f\u043e\u0434\u043d\u0435\u0441\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c &quot;QualPwn&quot;.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:14:26+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:14:26+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidad en los chips de Qualcomm que permite atacar dispositivos Android a trav\u00e9s de Wi-Fi | ProHoster","description":"Se han identificado tres vulnerabilidades en el stack inal\u00e1mbrico de chips Qualcomm, conocidas bajo el nombre en c\u00f3digo \"QualPwn\".","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0447\u0438\u043f\u0430\u0445 Qualcomm, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u0442\u044c Android-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u043e \u0447\u0435\u0440\u0435\u0437 Wi-Fi | ProHoster","og:description":"\u0412 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u043c \u0441\u0442\u0435\u043a\u0435 \u0447\u0438\u043f\u043e\u0432 Qualcomm \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0440\u0435\u043f\u043e\u0434\u043d\u0435\u0441\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c &quot;QualPwn&quot;.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-chipah-qualcomm-pozvolyayushhaya-atakovat-android-ustrojstvo-cherez-wi-fi","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:14:26+00:00","article:modified_time":"2019-10-31T19:14:26+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36876","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 05:09:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:37:23","updated":"2026-01-22 05:09:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/36876","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=36876"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/36876\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=36876"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=36876"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=36876"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}