๐Ÿ” CVE Alert

CVE-2022-24403

MEDIUM 4.3

De-anonymization attack in TETRA

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The TETRA TA61 identity encryption function internally uses a 64-bit value derived exclusively from the SCK (Class 2 networks) or CCK (Class 3 networks). The structure of TA61 allows for efficient recovery of this 64-bit value, allowing an adversary to encrypt or decrypt arbitrary identities given only three known encrypted/unencrypted identity pairs.

CWE CWE-327
Vendor etsi
Product tetra standard
Published Dec 5, 2023
Last Updated Aug 3, 2024
Stay Ahead of the Next One

Get instant alerts for etsi tetra standard

Be the first to know when new medium vulnerabilities affecting etsi tetra standard are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:U/RC:C/CR:H/IR:H/AR:H/MAV:A/MAC:L/MPR:N/MUI:N/MS:U/MC:L/MI:N/MA:N
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

ETSI / TETRA Standard
TA61

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
tetraburst.com: https://tetraburst.com/

Credits

Midnight Blue