芯片安全漏洞

Search documents
博通芯片,严重安全漏洞
半导体行业观察· 2025-08-07 01:48
Core Viewpoint - Dell computers using Broadcom chips have serious security vulnerabilities that could allow attackers to take control of millions of devices and steal sensitive data, including passwords and fingerprint information [2][3]. Group 1: Vulnerabilities and Impact - Five vulnerabilities (CVE-2025-24311, CVE-2025-25215, CVE-2025-24922, CVE-2025-25050, and CVE-2025-24919) exist in Broadcom BCM5820X series chips, primarily found in Dell's Latitude and Precision series laptops [2]. - These vulnerabilities could potentially allow non-administrator users to execute arbitrary code on the ControlVault firmware, leading to the exposure of critical security keys and persistent access to compromised machines [4][5]. Group 2: Response and Mitigation - Dell has notified customers about the vulnerabilities and is working with firmware providers to address the issues, urging customers to apply security updates promptly [3]. - Talos recommends disabling fingerprint login in high-risk environments to mitigate the risk of physical intrusion and suggests keeping systems updated with the latest firmware [5].