Cybersecurity researchers from the following organizations recently discovered the new 5Ghoul attack that impacts the 5G devices from popular brands:-.
5Ghoul exposes 5G vulnerabilities in Qualcomm and MediaTek modems, impacting smartphones, routers, and USB modems.
Twelve new vulnerabilities were discovered, with 10 affecting these major modems, three being highly severe.
5Ghoul uses a mimicked Dolev-Yao attacker model, exposing a controllable downlink channel to inject/modify 5G NR Downlink Packets without knowing the target UE's secret information.
The adversarial gNB manipulates downlink messages, enabling attacks at any 5G NR step, while later procedures face failure due to unknown SIM card details.
By deploying a malicious gNB using Software Defined Radio within the target 5G UE's radio range, the 5Ghoul vulnerabilities can be exploited easily over the air.
Despite the visual detectability of the USRP B210 in the researchers' setup, the miniaturized SDR equipment, like a Raspberry Pi, allows for stealthy and sophisticated attacks.
V5/V6 trigger temporary DoS on ARP5s, requiring continuous attacks for complete disruption.
V7 downgrades to 4G, forcing manual reboot for 5G restoration; persistent impact observed.
V8-V14 caused crashes on OnePlus with MediaTek Dimensity 900 5G Modem, necessitating modem reboots for 5G recovery.
Continuous attacks disrupt 3G/4G/5G communications on OnePlus, echoing V5/V6 behavior.
Exploitation on Specialized 5G Products: Vulnerabilities V5-V14 impact 5G devices with Qualcomm and MediaTek modems, affecting smartphones, USB modems, and low-latency communication appliances.
Downgrade Attacks: The vulnerability V7 acts as a downgrade attack, blocking 5G connections while allowing access to older technologies like 4G. This exposes users to different design issues inherent to various network technologies.
Estimating the reach of 5Ghoul: To gauge 5Ghoul's impact on 5G smartphones, we use web scraping to find models with vulnerable Qualcomm and MediaTek modems.
Mobile processors like Snapdragon 8XX or Dimensity XXXX integrate CPU, 5G modem, GPU, and peripherals, simplifying chipset identification.
The Challenge of Delivering 5G Patches to the End-user: Ensuring a secure modem SDK prevents prolonged vulnerabilities.
Issues in 5G modem implementation impact downstream vendors, causing delays in security updates due to software dependencies.
Here below, we have mentioned all the vulnerabilities that were described:-.
The potential of 5G is vast, but deeper research is crucial for uncovering vulnerabilities in its software.
The complex, multi-layered nature of 5G networks poses challenges, as seen in the discovery of 5Ghoul vulnerabilities in major chipset vendors despite their comprehensive testing resources.
This Cyber News was published on cybersecuritynews.com. Publication date: Mon, 11 Dec 2023 14:05:23 +0000