Logic Gone Astray: A Security Analysis Framework for the Control Plane Protocols of 5G Basebands

Year
2024
Type(s)
Author(s)
Kai Tu, Abdullah Al Ishtiaq, Syed Md Mukit Rashid, Yilu Dong, Weixuan Wang, Tianwei Wu, and Syed Rafiul Hussain
Source
USENIX Security Symposium (USENIX Security), 2024
Download FIle

Source code: https://github.com/SyNSec-den/5GBaseChecker

Reported 13 new 0-day vulnerabilities in 5G commercial basebands, 2024

  • CVD-2023-0081: GSMA Acknowledgment (known as Mobile Security Research Hall of Fame)
  • CVE-2023-52533, CVE-2023-52534, CVE-2023-52341, CVE-2023-52343, CVE-2023-52342, CVE-2023- 52344, CVE-2024-28818, CVE-2024-29152, CVE-2023-50803, CVE-2023-49927, CVE-2023-49928, CVE2023-50804
  • Samsung acknowledged us in the Samsung Product Security Update for helping them identify and fix several vulnerabilities in 5G baseband
  • Unisoc acknowledged us in Unisoc Product Security Acknowledgements for helping them identify and fix vulnerabilities in Unisoc 5G baseband implementations
  • $14,250 bug bounty from Google
  • $5,700 bug bounty from Samsung

 

News: