Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Summary

Researchers have identified a widespread class of 84 security vulnerabilities in 4G and 5G core networks. Exploiting these flaws could lead to denial-of-service attacks and session hijacking, enabling attackers to take over user network sessions.

IFF Assessment

FOE

The discovery of significant vulnerabilities in 4G and 5G core networks poses a direct threat to network security and user sessions, representing bad news for defenders.

Severity

8.2 High (AI Estimated)

The CVSS score is estimated to be high due to the potential for session hijacking and denial-of-service attacks, which can significantly impact confidentiality, integrity, and availability of network services. The widespread nature of the flaws also increases the risk.

Defender Context

The significant number of vulnerabilities discovered in 4G and 5G core networks highlights a critical area of risk for mobile network operators and users. Defenders should prioritize patching and implementing robust network segmentation and monitoring to mitigate the impact of potential denial-of-service and session hijacking attacks.

Read Full Story →