Downgrade Attacks via Rogue Base station


Threat Category: Cellular Air Interface


Threat Description:

Threat Origin

3G Security: Security Threats and Requirements (Release 4) 1

LTE Architecture Overview and Security Analysis (Draft NISTIR 8017) 2

LTE Security and Protocol Exploits 3

Exploit Examples

Researchers exploit cellular tech flaws to intercept phone calls 4

Every LTE call, text, can be intercepted, blacked out, hacker finds 5

CVE Examples

Not Applicable

Possible Countermeasures

Original Equipment Manufacturer

Ensure baseband firmware prevents the use of insecure cellular encryption algorithms

Mobile Network Operator

Use of application layer encryption technologies


