Dark Mode

Settings

Capec-606 Detail

Weakening of Cellular Encryption

Detailed Software Typical Severity: High

Parents: 620

Description

An attacker, with control of a Cellular Rogue Base Station or through cooperation with a Malicious Mobile Network Operator can force the mobile device (e.g., the retransmission device) to use no encryption (A5/0 mode) or to use easily breakable encryption (A5/1 or A5/2 mode).

Not present

External ID Source Link Description
CAPEC-606 capec https://capec.mitre.org/data/definitions/606.html
CWE-757 cwe http://cwe.mitre.org/data/definitions/757.html

Not present

  1. Cellular devices that allow negotiating security modes to facilitate backwards compatibility and roaming on legacy networks.

Not present

Medium
Adversaries can purchase and implement rogue BTS stations at a cost effective rate, and can push a mobile device to downgrade to a non-secure cellular protocol like 2G over GSM or CDMA.
Confidentiality
Other (Tracking, Network Reconnaissance)

Not present