Dark Mode
Capec-618 Detail
Cellular Broadcast Message Request
Detailed Communications Software Typical Severity: Low
Parents: 292
Threats: T60 T65 T80 T288 T291 T334 T392 T407
In this attack scenario, the attacker uses knowledge of the target’s mobile phone number (i.e., the number associated with the SIM used in the retransmission device) to cause the cellular network to send broadcast messages to alert the mobile device. Since the network knows which cell tower the target’s mobile device is attached to, the broadcast messages are only sent in the Location Area Code (LAC) where the target is currently located. By triggering the cellular broadcast message and then listening for the presence or absence of that message, an attacker could verify that the target is in (or not in) a given location.
Not present
| External ID | Source | Link | Description |
|---|---|---|---|
| CAPEC-618 | capec | https://capec.mitre.org/data/definitions/618.html | |
| CWE-201 | cwe | http://cwe.mitre.org/data/definitions/201.html | |
| REF-487 | reference_from_CAPEC | https://www-users.cs.umn.edu/~hoppernj/celluloc.pdf | Denis Foo Kune, John Koelndorfer, Nicholas Hopper, Yongdae Kim, Location Leaks on the GSM Air Interface, University of Minnesota |
Not present
- The attacker must have knowledge of the target’s mobile phone number.
Not present
| Low |
|---|
| Open source and commercial tools are available for this attack. |
| Other |
|---|
| Other (An attacker could verify that the target is in (or not in) a given location.) |
Not present