Cracking the 5G Fortress: Peering Into 5G’s Vulnerability Abyss

Year
2024
Type(s)
Author(s)
Kai Tu, Abdullah Al Ishtiaq, Syed Md Mukit Rashid, Yilu Dong, Weixuan Wang, Tianwei Wu, and Syed Rafiul Hussain
Source
BlackHat USA, 2024
Url(s)
https://www.blackhat.com/us-24/briefings/schedule/index.html#cracking-the-g-fortress-peering-into-gs-vulnerability-abyss-40620

Source code: https://github.com/SyNSec-den/5GBaseChecker

Reported 13 new 0-day vulnerabilities in 5G commercial basebands, 2024

  • CVD-2023-0081: GSMA Acknowledgment (known as Mobile Security Research Hall of Fame)
  • CVE-2023-52533, CVE-2023-52534, CVE-2023-52341, CVE-2023-52343, CVE-2023-52342, CVE-2023- 52344, CVE-2024-28818, CVE-2024-29152, CVE-2023-50803, CVE-2023-49927, CVE-2023-49928, CVE2023-50804
  • Samsung acknowledged us in the Samsung Product Security Update for helping them identify and fix several vulnerabilities in 5G baseband
  • Unisoc acknowledged us in Unisoc Product Security Acknowledgements for helping them identify and fix vulnerabilities in Unisoc 5G baseband implementations
  • $14,250 bug bounty from Google
  • $5,700 bug bounty from Samsung

 

News: 

 

Leave a Reply

Your email address will not be published. Required fields are marked *