DCK pinning attack in TETRA
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
In short
A weakness in TETRA's authentication lets an attacker who can predict a specific challenge value intercept communications and force the session key to zero, making encrypted conversations readable.
Technical detail
The vulnerability exploits predictability of the MS challenge RAND2 in TETRA's authentication procedure, allowing a man-in-the-middle adversary to manipulate the Derived Cipher Key (DCK) negotiation to a null state, thereby compromising session encryption without detection.
Summary generated and translated by AI from the official description.
A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set session key DCK to zero.
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R/CR:H/IR:H/AR:H/MAV:A/MAC:H/MPR:N/MUI:N/MS:U/MC:H/MI:H/MA:H
Affected products
ETSI · TETRA StandardReferences
https://tetraburst.com/