• About
  • Disclaimer
  • Privacy Policy
  • Contact
Sunday, June 15, 2025
Cyber Defense GO
  • Login
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration
No Result
View All Result
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration
No Result
View All Result
Cyber Defense Go
No Result
View All Result
Home Cyber Security

Over 100 Safety Flaws Present in LTE and 5G Community Implementations

Md Sazzad Hossain by Md Sazzad Hossain
0
Over 100 Safety Flaws Present in LTE and 5G Community Implementations
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter


Jan 24, 2025Ravie LakshmananTelecom Safety / Vulnerability

LTE and 5G Network Implementations

A gaggle of teachers has disclosed particulars of over 100 safety vulnerabilities impacting LTE and 5G implementations that might be exploited by an attacker to disrupt entry to service and even achieve a foothold into the mobile core community.

The 119 vulnerabilities, assigned 97 distinctive CVE identifiers, span seven LTE implementations – Open5GS, Magma, OpenAirInterface, Athonet, SD-Core, NextEPC, srsRAN – and three 5G implementations – Open5GS, Magma, OpenAirInterface, in response to researchers from the College of Florida and North Carolina State College.

Cybersecurity

The findings have been detailed in a examine titled “RANsacked: A Area-Knowledgeable Method for Fuzzing LTE and 5G RAN-Core Interfaces.”

“Each one of many >100 vulnerabilities mentioned beneath can be utilized to persistently disrupt all mobile communications (telephone calls, messaging and information) at a city-wide degree,” the researchers mentioned.

“An attacker can repeatedly crash the Mobility Administration Entity (MME) or Entry and Mobility Administration Operate (AMF) in an LTE/5G community, respectively, just by sending a single small information packet over the community as an unauthenticated consumer (no SIM card required).”

The invention is the results of a fuzzing train, dubbed RANsacked, undertaken by the researchers in opposition to Radio Entry Community (RAN)-Core interfaces which can be able to receiving enter straight from cell handsets and base stations.

The researchers mentioned a number of of the recognized vulnerabilities relate to buffer overflows and reminiscence corruption errors that might be weaponized to breach the mobile core community, and leverage that entry to watch cellphone location and connection info for all subscribers at a city-wide degree, perform focused assaults on particular subscribers, and carry out additional malicious actions on the community itself.

What’s extra, the recognized flaws fall beneath two broad classes: These that may be exploited by any unauthenticated cell system and people that may be weaponized by an adversary who has compromised a base station or a femtocell.

Cybersecurity

Of the 119 vulnerabilities found, 79 had been present in MME implementations, 36 in AMF implementations, and 4 in SGW implementations. Twenty-five shortcomings result in Non-Entry Stratum (NAS) pre-authentication assaults that may be carried out by an arbitrary cellphone.

“The introduction of home-use femtocells, adopted by extra easily-accessible gNodeB base stations in 5G deployments, symbolize an extra shift in safety dynamics: the place as soon as bodily locked-down, RAN tools is now overtly uncovered to bodily adversarial threats,” the examine famous.

“Our work explores the implications of this ultimate space by enabling performant fuzzing interfaces which have traditionally been assumed implicitly safe however now face imminent threats.”

Discovered this text attention-grabbing? Comply with us on Twitter  and LinkedIn to learn extra unique content material we submit.



You might also like

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board

Discord Invite Hyperlink Hijacking Delivers AsyncRAT and Skuld Stealer Concentrating on Crypto Wallets

Why Each Enterprise Wants a Regulatory & Compliance Lawyer—and the Proper IT Infrastructure to Assist Them

Tags: FlawsImplementationsLTENetworkSecurity
Previous Post

AI Maps Titan’s Methane Clouds in Report Time

Next Post

What Is Beamforming? How Does Beamforming Work?

Md Sazzad Hossain

Md Sazzad Hossain

Related Posts

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board
Cyber Security

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board

by Md Sazzad Hossain
June 15, 2025
Discord Invite Hyperlink Hijacking Delivers AsyncRAT and Skuld Stealer Concentrating on Crypto Wallets
Cyber Security

Discord Invite Hyperlink Hijacking Delivers AsyncRAT and Skuld Stealer Concentrating on Crypto Wallets

by Md Sazzad Hossain
June 14, 2025
The Carruth Knowledge Breach: What Oregon Faculty Staff Must Know
Cyber Security

Why Each Enterprise Wants a Regulatory & Compliance Lawyer—and the Proper IT Infrastructure to Assist Them

by Md Sazzad Hossain
June 14, 2025
Detecting Ransomware on Community: How Community Site visitors Evaluation Helps
Cyber Security

Detecting Ransomware on Community: How Community Site visitors Evaluation Helps

by Md Sazzad Hossain
June 13, 2025
What’s Zero Belief Structure? A Newbie’s Information
Cyber Security

What’s Zero Belief Structure? A Newbie’s Information

by Md Sazzad Hossain
June 13, 2025
Next Post
What Is Beamforming? How Does Beamforming Work?

What Is Beamforming? How Does Beamforming Work?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

On the core of problem-solving | MIT Information

On the core of problem-solving | MIT Information

March 24, 2025
UFO2 turns your desktop into an agent playground

UFO2 turns your desktop into an agent playground

April 24, 2025

Categories

  • Artificial Intelligence
  • Computer Networking
  • Cyber Security
  • Data Analysis
  • Disaster Restoration
  • Machine Learning

CyberDefenseGo

Welcome to CyberDefenseGo. We are a passionate team of technology enthusiasts, cybersecurity experts, and AI innovators dedicated to delivering high-quality, insightful content that helps individuals and organizations stay ahead of the ever-evolving digital landscape.

Recent

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board

June 15, 2025

Ctrl-Crash: Ny teknik för realistisk simulering av bilolyckor på video

June 15, 2025

Search

No Result
View All Result

© 2025 CyberDefenseGo - All Rights Reserved

No Result
View All Result
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration

© 2025 CyberDefenseGo - All Rights Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In