EVå é»éä¿¡å®è£ ã«ãããè匱æ§ã®çºèŠãšSLACã®æè¡çèå¯
æè¿ãPlaxidityXã®ãªãµãŒãããŒã ã«ããæ°ããªè匱æ§ïŒCVE-2025-27071ïŒãçºèŠãããŸãããæ¬è匱æ§ã¯ãEVãšå é»ã¹ããŒã·ã§ã³éã®éä¿¡å®è£ ã«ãããéå€§ãªæ¬ é¥ãæããã«ãããã®ã§ããããã¯ãSLACãããã³ã«ã®ãªãŒãã³ãœãŒã¹å®è£ ã§ããopen-plc-utilsã«ååšããã¹ã¿ãã¯ããŒã¹ã®ãããã¡ãªãŒããŒãããŒã®è匱æ§ã§ã黿°èªåè»ïŒEVïŒããã³å é»èšåïŒEVSEïŒã®åæ¹ã«åœ±é¿ãåãŒããŸããæ»æè ããããæªçšããå Žåã察象æ©åšäžã§ä»»æã®ã³ãŒããå®è¡ãããæãããããŸããæ¬ä»¶ã¯ãEVå é»ã€ã³ãã©ã«ãããéä¿¡å®è£ ã®ãµã€ããŒã»ãã¥ãªãã£ãªã¹ã¯ãå ·äœçã«ç€ºãäºäŸã§ããå é»ãããã¯ãŒã¯å šäœã«ãããŠãå®è£ ã¬ãã«ã§ã®ã»ãã¥ãªãã£å¯Ÿçã匷åããå¿ èŠããããŸãã
EVã®æ®åãå éããäžãè»äž¡ãšå é»ã¹ããŒã·ã§ã³éã®å®å šãªéä¿¡ã¯ãããŸã§ä»¥äžã«éèŠã«ãªã£ãŠããŸããç¹ã«Vehicle-to-GridïŒV2GïŒã®çµ±åãé²ãçŸåšãéä¿¡ã®ä¿¡é Œæ§ãšå®å šæ§ã¯ã€ã³ãã©å šäœã®å®å®éçšãå·Šå³ããŸããISO 15118ã¯ãé察称æå·æè¡ãèªèšŒãæå·åãéããŠã·ãŒã ã¬ã¹ãã€å®å šãªå é»ãå®çŸããããã®åœéæšæºã§ããããããã®ã»ãã¥ãªãã£èŠä»¶ãå®è£ ã¬ãã«ã§ç¢ºå®ã«åæ ãããããšã¯å®¹æã§ã¯ãããŸããã
æ¬èšäºã§ã¯ãåœç€ŸãªãµãŒãããŒã ãçºèŠããEVãšå é»ã¹ããŒã·ã§ã³éã®éä¿¡ãããã³ã«å®è£ ã«ãããé倧ãªè匱æ§ïŒCVE-2025-27071ïŒã«ã€ããŠè§£èª¬ããŸãããã®ãããã¡ãªãŒããŒãããŒã®æ¬ é¥ã«ããã察象æ©åšäžã§æ»æè ãä»»æã®ã³ãŒããå®è¡ã§ããæãããããŸããæ¬ä»¶ã¯2024幎12æã«Qualcommãžå ±åããããã®åŸã»ãã¥ãªãã£ã¢ããã€ã¶ãªã®å ¬éããªãŒãã³ãœãŒã¹ãããžã§ã¯ãã«å¯ŸãããããæäŸã2025幎ã«å®æœãããŠããŸãã
èæ¯ïŒEVãšå é»ã¹ããŒã·ã§ã³éã®éä¿¡ã«ãããä¿¡é Œæ§ã®éèŠæ§
EVã§ã¯ãDIN SPEC 70121ããã³ISO 15118ã§å®çŸ©ãããVehicle-to-GridïŒV2GïŒãããã³ã«çŸ€ã«åºã¥ãé«ã¬ãã«éä¿¡ãè¡ãããŠããŸãããã®éä¿¡ææ®µãšããŠãPower Line CommunicationïŒPLCïŒãå©çšãããŠããŸããç¹ã«åçšã®å é»ã¹ããŒã·ã§ã³ã«ãããŠã¯ãEVãšé»åã°ãªããã«æ¥ç¶ãããè€æ°ã®å é»èšåãšã®éã§ãèªèšŒã決æžåŠçãå é»ã¹ã±ãžã¥ãŒã«ã®èª¿æŽãšãã£ãããžã¿ã«éä¿¡ã確ç«ããå¿ èŠããããŸãã
ãã®PLCéä¿¡ã®å®å®æ§ãšä¿¡é Œæ§ãæ ä¿ããããã«çšããããŠããã®ããSignal Level Attenuation CharacterizationïŒSLACïŒã§ããSLACã¯V2Gã¹ã¿ãã¯ã«å«ãŸãããããã³ã«ã®äžã€ã§ãããé»åç·äžã®ãã€ãºãä¿¡å·æžè¡°ã®åœ±é¿ã«ãã£ãŠãEVãæ¥ç¶ãã¹ãã§ã¯ãªãå é»ã¹ããŒã·ã§ã³ãšéä¿¡ããŠããŸãããšãé²ã圹å²ãæãããŸããå ·äœçã«ã¯ãIPéä¿¡ãéå§ããåæ®µéã§ãEVãšå é»ã¹ããŒã·ã§ã³ã®éã§Ethernetã¬ãã«ã®ãããŒããã£ã¹ãã¡ãã»ãŒãžãæ°åããåããããã³ãã·ã§ã€ã¯ã確ç«ããŸãããã®ããã»ã¹ã«ãããEVã¯ã°ãªããå ã®å é»èšåãç¹å®ããå®å®ããéä¿¡çµè·¯ã確ç«ããããšãå¯èœãšãªããŸãã
è匱æ§ã®æŠèŠïŒãªãŒãã³ãœãŒã¹PLCãã¡ãŒã ãŠã§ã¢ã«ããããããã¡ãªãŒããŒãããŒïŒCVE-2025-27071ïŒ
open-plc-utils ã¯ãQualcomm Atheros Powerline Toolkitã®ãªãŒãã³ãœãŒã¹çãšããŠæäŸãããŠãããœãããŠã§ã¢ããŒã«çŸ€ã§ããplcboot(1) ãªã©ã®ããŒã«ãéããŠãAtherosããã³Qualcomm補ãããã»ããã«ããPLCæ©èœã®å¶åŸ¡ãæäœãè¡ãããèšèšãããŠããŸãããŸããEVããã³EVSEåãã®SLACãããã³ã«å®è£ ãå«ãŸããŠããŸããEVåŽã®SLACæ©èœã¯äžè¬ã«RTOSç°å¢ïŒAUTOSARãªã©ïŒäžã§å®è£ ãããããšãå€ãäžæ¹ãLinuxããŒã¹ã§æ§ç¯ãããEVSEã§ã¯open-plc-utilsãå©çšãããã±ãŒã¹ãå€ããããŸãã
SLACãããã³ã«ã§å®çŸ©ãããã¡ãã»ãŒãžã®å€ãã¯åºå®é·ã§ãããäŸå€ãšããŠä¿¡å·æžè¡°ã®æž¬å®å€ãå«ãã¡ãã»ãŒãžã¯å¯å€é·ãšãªã£ãŠããŸããEVãå é»ã¹ããŒã·ã§ã³ã«PLCä¿¡å·ã®æžè¡°æž¬å®å€ãéä¿¡ããéãéåžžã¯58åã®åšæ³¢æ°ã°ã«ãŒãããšã®æžè¡°å€ãå«ãŸããŸããæžè¡°æž¬å®ã¡ãã»ãŒãžã«ã¯ãè€æ°ã®æžè¡°å€ãé£ç¶ããŠæ ŒçŽãããŠããããã®æ«å°Ÿã«ãNumber of Groupsããšãã1ãã€ãã®ãã£ãŒã«ããé 眮ãããŠããŸãããã®ãã£ãŒã«ãã¯ããã±ããå ã«å«ãŸããæžè¡°å€ã®æ°ã瀺ããŸããäŸãã°ããã®å€ã58ã§ããã°ã58ååã®ããŒã¿ããã±ããã«å«ãŸããŠããããšãæå³ããŸãã
åœç€ŸãªãµãŒãããŒã ãçºèŠããã®ã¯ãopen-plc-utilsã«ãããSLACãããã³ã«å®è£ å ã®ã¹ã¿ãã¯ããŒã¹ã®ãããã¡ãªãŒããŒãããŒã§ããæ¬è匱æ§ã¯ãEVåŽããã³EVSEåŽã®åæ¹ã«ååšããŠããŸãããæ ¹æ¬çãªåé¡ã¯ãå¯å€é·é åã®ãµã€ãºã瀺ããNumber of Groupsãã®å€ã«å¯ŸããŠé©åãªæ€èšŒãè¡ãããŠããªãç¹ã«ãããŸãããã®å€ã¯å ¥åæ€èšŒãããªããŸãŸãåŸç¶ã® memcpy åŠçã«ãã®ãŸãŸäœ¿çšãããŠããŸããããã®çµæãæ»æè ãæå³çã«ç°åžžãªãµã€ãºå€ãå«ããã±ãããéä¿¡ããå Žåããããã¡å¢çãè¶ ããæžã蟌ã¿ãçºçããã¹ã¿ãã¯é åãç Žå£ãããæãããããŸãã
EVåŽãžã®åœ±é¿
EVåŽã§ã¯ãå é»ã¹ããŒã·ã§ã³ïŒEVSEïŒããéä¿¡ããã CM_ATTEN_CHAR_IND ã¡ãã»ãŒãžãåä¿¡ã»è§£æããŸãããã®ã¡ãã»ãŒãžã«ã¯ãEVSEããEVãžæž¡ãããå¯å€é·ãã©ã¡ãŒã¿ãNumber of GroupsïŒNumGroupsïŒããå«ãŸããŠããŸãã
åé¡ãšãªãã®ã¯ããã® NumGroups ã®æ±ãã§ããã³ãŒãäžã§ã¯ãåä¿¡ã¡ãã»ãŒãžã cm_atten_char_indicate æ§é äœãšããŠãã£ã¹ãããããããNumGroupsã®å€ãçŽæ¥ååŸããŠããŸãããããŠããã®å€ãå¢çãã§ãã¯ãªãã§çŽåŸã® memcpy ã«äœ¿çšããŠããŸãããã®çµæãã³ããŒå
ãããã¡ïŒãã®å Žå㯠session->AAGïŒã®ãµã€ãºãè¶
ããããŒã¿ãæžã蟌ãŸããæããããããããã¡ãªãŒããŒãããŒãçºçããŸãã
ããã«éèŠãªã®ã¯ãsession 倿°ãã¡ã€ã³é¢æ°ã®ã¹ã¿ãã¯é åã«ç¢ºä¿ãããŠããç¹ã§ãã
ãªããå®éã«æªçšã®å¯èœæ§ã¯ã³ã³ãã€ã«ç°å¢ïŒ32bitïŒ64bitã倿°ã¢ã©ã€ã³ã¡ã³ããã¹ã¿ãã¯é 眮ãªã©ïŒãã¡ã¢ãªé çœ®ã®æ¡ä»¶ã«å·Šå³ãããŸããæ¬ä»¶ã§ã¯ãæ»æè ãå¶åŸ¡å¯èœãªããŒã¿éãæå€§255ãã€ãã§ããäžæ¹ã圱é¿ãåããæ§é äœèªäœã¯ãã以äžã®ãµã€ãºãæã£ãŠããŸãããã®ãããåçŽã«ãªã¿ãŒã³ã¢ãã¬ã¹ãæžãæããå žåçãªæ»æãçŽã¡ã«æç«ãããšã¯éããŸãããã ãããšèšã£ãŠãæ§é äœå ã®ä»ã®ãã£ãŒã«ããæžãæãããªã©ãä»ã®å¶åŸ¡ããŒã¿ãæžãæããããšã§æªçšãããæãã¯åŠå®ã§ããŸããã
EVSEåŽãžã®åœ±é¿
EVSEåŽã§ããEVãšåæ§ã®ãã¿ãŒã³ã§è匱æ§ã確èªãããŠããŸããå ·äœçã«ã¯ããã±ããå ã® numGroups ãã£ãŒã«ãã«å¯Ÿããå¢çãã§ãã¯ãæ¬ èœããŠããããã®çµæãšããŠãããã¡ãªãŒããŒãããŒãçºçããæãããããŸãã該åœç®æã¯ evse_cm_mnbc_sounds 颿°å ã§ç¢ºèªãããŠããŸããEVSEåŽã§ã¯ãåä¿¡ããæžè¡°ç¹æ§ã¡ãã»ãŒãžããããŒã¿ãã¹ã¿ãã¯äžã®ãµã€ãº58ãã€ãã®ãããã¡ã«ã³ããŒããåŠçã«ãããŠãæ»æè ãæäœå¯èœãª numGroups ã®å€ãå¢çãã§ãã¯ãªãã« forã«ãŒãã®ç¹°ãè¿ãåæ°ãšããŠäœ¿ãããŠããŸããã
ãã®é¢æ°ã«ãããã¹ã¿ãã¯äœ¿çšéã¯ããããã255ãã€ãæªæºãšèŠç©ããããšãã§ããã¹ã¿ãã¯äžã«ç¢ºä¿ãããã¡ã¢ãªé åãæ¯èŒçå°ãããããæ»æè ãæäœã§ããããŒã¿ã«ãã£ãŠéèŠãªå¶åŸ¡æ å ±ã«å°éããããæ§é ã«ãªã£ãŠããŸãããã®ãããEVåŽãšæ¯ã¹ãŠæªçšã®å¯èœæ§ãæ³å®ããããç¶æ³ã«ãããšèšããŸãããã¡ããå®éã®æ»ææç«å¯åŠã¯ãã³ã³ãã€ã«èšå®ãä¿è·æ©æ§ïŒStack CanaryãASLRãNXãªã©ïŒãåŒã³åºãèŠçŽãæé©åã®æç¡ãšãã£ãæ¡ä»¶ã«å·Šå³ãããŸããããããå€éšããäžããããå€ãæ€èšŒããã«ã«ãŒãåæ°ãšããŠäœ¿çšããèšèšèªäœããå žåçãªã¡ã¢ãªç Žå£ãã°ã®åå ã«ã€ãªããåŸãèšèšã§ããããšã¯æããã§ãã
ãŸãšã
open-plc-utilsãããžã§ã¯ãã«ãããSLACã¢ãžã¥ãŒã«ã®æçµæŽæ°ã¯ã2013幎ã«é¡ããŸãããã§ã«12幎以äžãçµéããŠãããçŸåšã®ãªãœãŒã¹å¶çŽãå³ããEVåãå é»éä¿¡ECUã«ãã®ãŸãŸçµã¿èŸŒãŸããŠããå¯èœæ§ã¯é«ããªããããããŸãããããããªãããæ¬è匱æ§ã®éèŠæ§ãäœãããã§ã¯ãããŸãããå®éã«ã¯ãåã¢ãžã¥ãŒã«ã¯çŸåšãLinuxããŒã¹ã®å é»ã¹ããŒã·ã§ã³ã€ã³ãã©ã§åºãå©çšãããŠããã±ãŒã¹ãããããã§ããã€ãŸãã圱é¿ç¯å²ã¯äŸç¶ãšããŠçŸå®çãã€å®éçšç°å¢ã«çŽçµããŠããŸãã
ãªããæ¬è匱æ§ïŒCVE-2025-27071ïŒã¯QualcommãžçŽæ¥å ±åãããå瀟ã®å éšPLCããŒã«ã«ã€ããŠãä¿®æ£ã宿œãããŸããã責任ããé瀺ããã»ã¹ãéããŠä¿®æ£å¯Ÿå¿ãè¡ãããããšã¯ããšã³ã·ã¹ãã å šäœã®ã»ãã¥ãªãã£åŒ·åã«åããéèŠãªäžæ©ãšãããŸãã
PlaxidityX ãµã€ããŒã»ãã¥ãªãã£ãªãµãŒãïŒãœãªã¥ãŒã·ã§ã³ããŒã ã«ã€ããŠ
PlaxidityXã®ãµã€ããŒã»ãã¥ãªã㣠ãªãµãŒãïŒãœãªã¥ãŒã·ã§ã³ããŒã ã¯ãèªåè»æ¥çã«ç¹åãããµã€ããŒã»ãã¥ãªãã£ã®ç ç©¶ããã³ãœãªã¥ãŒã·ã§ã³æäŸãè¡ã£ãŠããŸããè»äž¡ã¢ãŒããã¯ãã£ãéä¿¡ãããã³ã«ãé¢é£èŠæ Œã«å¯Ÿããæ·±ãçè§£ãåºç€ã«ãå æ¬çãªãµã€ããŒã»ãã¥ãªãã£ãµãŒãã¹ãæäŸããŠããŸãã
ããŒã ã¯ãè»äž¡ãšã³ã·ã¹ãã å šäœã察象ãšããã»ãã¥ãªãã£è©äŸ¡ã»ãœãªã¥ãŒã·ã§ã³ã«åãçµãã§ããŸããããããŸã§ã«äž»èŠèªåè»ã¡ãŒã«ãŒããã³Tier 1ãµãã©ã€ã€ãŒãšå€æ°ã®ãããã¬ãŒã·ã§ã³ãã¹ãããã³ç ç©¶ãããžã§ã¯ãã宿œããå®ç°å¢ãæ³å®ããæ€èšŒãéããŠèšèšäžã®èª²é¡æœåºãšæ¹åæ¯æŽãè¡ã£ãŠããŸãããŸããUN R155ãISO 21434ãšãã£ãåœéèŠå¶ã»æšæºãžã®å¯Ÿå¿æ¯æŽãå«ããéçºããã»ã¹å šäœã«çµã¿èŸŒãŸããã»ãã¥ãªãã£äœå¶ã®æ§ç¯ããµããŒãããŠããŸãã
ãªãµãŒããããžã§ã¯ãã®å®æœãããPlaxidityXã®å é²çãªè£œåå°å ¥ãŸã§ãé²åããè åšã«å¯Ÿå¿ããããã®ç¥èŠãšæè¡ãæäŸããè»äž¡ã©ã€ããµã€ã¯ã«å šäœã«ãããã»ãã¥ãªãã£ç¢ºä¿ãæ¯æŽããŸãã
å·çïŒ2026幎02æ24æ¥