'5Ghoul' Vulnerabilities Haunt Qualcomm, MediaTek 5G Modems

Academic researchers from the ASSET Research Group at the Singapore University of Technology and Design are raising an alarm for more than a dozen vulnerabilities plaguing hundreds of smartphone models that employ specific 5G modems.
Collectively tagged as 5Ghoul, the 14 security defects can be exploited to drop and freeze 5G connections on smartphones and routers, and to conduct downgrading attacks, according to the research team.
The majority of the flaws affect 5G modems from Qualcomm and MediaTek.
A typical exploit of the 5Ghoul vulnerabilities relies on a malicious base station meant to 'distract' devices that employ vulnerable 5G modems into connecting to it.
Once the connection is established, the flaws are exploited to target the devices' connections, eventually forcing the users to manually reboot them.
The attacker could use software defined radio equipment, which may be the size of a Raspberry Pi, to behave like a cloned gNB, making the attack stealthy.
The targeted flaws, 12 of which are new, were identified in the 5G baseband modem firmware, meaning that all products using the affected modems are vulnerable.
Most of the security holes impact the radio resource control attach procedure, which contains the RRC connection setup message.
The vulnerabilities can be triggered via malformed RRC connection setup messages or crafted NAS authentication requests.
Patches for the 5Ghoul bugs are expected to reach Android smartphones this month.
Vulnerabilities impacting Apple devices will be addressed at another time.
Three of the bugs - CVE-2023-33042, CVE-2023-33043, and CVE-2023-33044 - were identified in Qualcomm modems.
The chip maker mentioned them in its December 2023 security bulletin, warning that more than 70 chipset models are affected.
In its December 2023 security bulletin, the company warned that more than 30 chipset models are affected.
The researchers estimate that more than 700 smartphone models are affected, with devices from Vivo, Xiaomi, Oppo, Samsung, and Honor being impacted the most.
Roughly 1.7% of the affected devices are iPhones.
The academics also warn that the 5Ghoul vulnerabilities impact other types of devices as well, due to their use of vulnerable 5G modems.
Industrial IoT solutions are also affected, such as Qualcomm's 315 5G IoT modem.


This Cyber News was published on www.securityweek.com. Publication date: Mon, 11 Dec 2023 21:43:04 +0000


Cyber News related to '5Ghoul' Vulnerabilities Haunt Qualcomm, MediaTek 5G Modems