Close Menu
5gantennas.org5gantennas.org
  • Home
  • 5G
    • 5G Technology
  • 6G
  • AI
  • Data
    • Global 5G
  • Internet
  • WIFI
  • 5G Antennas
  • Legacy

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
5gantennas.org5gantennas.org
  • Home
  • 5G
    1. 5G Technology
    2. View All

    Deutsche Telekom to operate 12,500 5G antennas over 3.6 GHz band

    August 28, 2024

    URCA Releases Draft “Roadmap” for 5G Rollout in the Bahamas – Eye Witness News

    August 23, 2024

    Smart Launches Smart ZTE Blade A75 5G » YugaTech

    August 22, 2024

    5G Drone Integration Denmark – DRONELIFE

    August 21, 2024

    Hughes praises successful private 5G demo for U.S. Navy

    August 29, 2024

    GSA survey reveals 5G FWA has become “mainstream”

    August 29, 2024

    China Mobile expands 5G Advanced, Chunghwa Telecom enters Europe

    August 29, 2024

    Ateme and ORS Boost 5G Broadcast Capacity with “World’s First Trial of IP-Based Statmux over 5G Broadcast” | TV Tech

    August 29, 2024
  • 6G

    India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

    August 29, 2024

    Vodafonewatch Weekly: Rural 4G, Industrial 5G, 6G Patents | Weekly Briefing

    August 29, 2024

    Southeast Asia steps up efforts to build 6G standards

    August 29, 2024

    Energy efficiency as an inherent attribute of 6G networks

    August 29, 2024

    Finnish working group launches push for 6G technology

    August 28, 2024
  • AI

    Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

    August 29, 2024

    Why Honeywell is betting big on Gen AI

    August 29, 2024

    Ethically questionable or creative genius? How artists are engaging with AI in their work | Art and Design

    August 29, 2024

    “Elon Musk and Trump” arrested for burglary in disturbing AI video

    August 29, 2024

    Nvidia CFO says ‘enterprise AI wave’ has begun and Fortune 100 companies are leading the way

    August 29, 2024
  • Data
    1. Global 5G
    2. View All

    Global 5G Enterprise Market is expected to be valued at USD 34.4 Billion by 2032

    August 12, 2024

    Counterpoint predicts 5G will dominate the smartphone market in early 2024

    August 5, 2024

    Qualcomm’s new chipsets will power affordable 5G smartphones

    July 31, 2024

    Best Super Fast Download Companies — TradingView

    July 31, 2024

    Crypto Markets Rise on Strong US Economic Data

    August 29, 2024

    Microsoft approves construction of third section of Mount Pleasant data center campus

    August 29, 2024

    China has invested $6.1 billion in state-run data center projects over two years, with the “East Data, West Computing” initiative aimed at capitalizing on the country’s untapped land.

    August 29, 2024

    What is the size of the clinical data analysis solutions market?

    August 29, 2024
  • Internet

    NATO believes Russia poses a threat to Western internet and GPS services

    August 29, 2024

    Mpeppe grows fast, building traction among Internet computer owners

    August 29, 2024

    Internet Computer Whale Buys Mpeppe (MPEPE) at 340x ROI

    August 29, 2024

    Long-term internet computer investor adds PEPE rival to holdings

    August 29, 2024

    Biden-Harris Administration Approves Initial Internet for All Proposals in Mississippi and South Dakota

    August 29, 2024
  • WIFI

    4 Best Wi-Fi Mesh Networking Systems in 2024

    September 6, 2024

    Best WiFi deal: Save $200 on the Starlink Standard Kit AX

    August 29, 2024

    Sonos Roam 2 review | Good Housekeeping UK

    August 29, 2024

    Popular WiFi extender that eliminates dead zones in your home costs just $12

    August 29, 2024

    North American WiFi 6 Mesh Router Market Size, Share, Forecast, [2030] – அக்னி செய்திகள்

    August 29, 2024
  • 5G Antennas

    Nokia and Claro bring 5G to Argentina

    August 27, 2024

    Nokia expands FWA portfolio with new 5G devices – SatNews

    July 25, 2024

    Deutsche Telekom to operate 12,150 5G antennas over 3.6 GHz band

    July 24, 2024

    Vodafone and Ericsson develop a compact 5G antenna in Germany

    July 12, 2024

    Vodafone and Ericsson unveil new small antennas to power Germany’s 5G network

    July 11, 2024
  • Legacy
5gantennas.org5gantennas.org
Home»5G Technology»5G Core ASN.1 Vulnerability
5G Technology

5G Core ASN.1 Vulnerability

5gantennas.orgBy 5gantennas.orgOctober 20, 2023No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


NGAP is a control plane (signaling) protocol that runs on SCTP port 38412. GTP-U is a user data encapsulation protocol that runs on UDP port 2152. Control plane signaling from the UE is handled by the baseband modem.

Users do not have access to baseband modems. User plane traffic (data sent by users, such as browsing and streaming) is sent to the User Plane Function (UPF) via a GTP-U tunnel. In the 5G Control Plane User Plane Separation (CUPS) architecture, UPF and AMF are functionally separated. These are separate network functions with their own IP addresses. User data sent to the control plane is a security risk because regular users do not have permission to access the network infrastructure.

I was able to establish an SCTP connection with AMF from the UE application layer. An abnormal NGAP payload was sent over this SCTP connection. From the 5GC side, the packet appears as NGAP-in-GTPU. This NGAP message was delivered to AMF and caused a crash.

The most concerning weakness here is the routing of user plane messages. This could result in anomalous signaling messages being delivered to AMF. A prerequisite for the attack is that the attacker must know her AMF IP address. This was achieved using her SCTP scan over the user plane.

Please note that this test was performed using the free5gc all-in-one virtual machine, not the containerized version. These have different routing settings.

In our test case, we exploited the lack of separation between the control plane and the user plane and used user traffic from user equipment as an attack vector.

There are two problems here.

  • ASN.1 parser was not robust
  • Control plane and user plane were not properly separated.

The first problem may be related to coding. ASN.1 decoders used to parse control plane messages are complex and often vulnerable to malformed messages.

The second issue is an architectural issue that allows user traffic to infiltrate the control plane, which can cause further problems.

Even if the control plane and user plane are properly separated, malformed N1 messages can be sent by the UE and cause a crash. For this purpose, the UE requires the ability to create control messages. There are open source solutions (such as srsUE) that can do this.

The free5GC project is one of the most popular open source implementations of 5G cores. We are aware of commercial solutions based on free5GC from major packet core vendors targeting the private 5G market and the telecom industry. In fact, there are defense agencies in Asia and Europe that are acquiring 5G network products from such vendors.

CVE-2022-43677 The vulnerability exploits a weak CUPS implementation in free5gc to trigger a control plane denial of service (DoS) through user traffic. A successful DoS attack on the packet core disrupts connectivity for the entire network. In critical sectors such as defence, police, mining and traffic control, connectivity disruptions have dire consequences. For factories that use real-time sensors in their manufacturing processes, this can result in defective products.

Recommendations and insights

We recommend the following best practices for users of the technologies described in this blog entry:

  • access control: Ensures that only trusted devices can connect to your network. SIM card registration and use must be strictly regulated and controlled.
  • Clear separation of control plane and data plane: Plane separation within the packet core prevents data packets from being passed to the control plane.
  • open source, responsible: When using open source software to create critical infrastructure nodes, users must be able to immediately apply patches to prevent defects. We strongly recommend that users thoroughly study and understand the underlying code or, if not, obtain dedicated support for the software they use.
  • Use a CT-enabled DPI solution/firewall: Frequently updating critical infrastructure nodes is not trivial as it can lead to service interruptions. Virtual patching tailored to the packet core is highly recommended. Detects abnormal NGAP messages on N2. In N3, beware of exploiting GTP-U tunnels (NGAP within GTP-U, GTP-U within GTP-U).

We recommend using a multi-layered security solution that combines security and visibility of IT and communication technologies. Implementing a Zero Trust solution such as Trend Micro™ Mobile Network Security powered by CTOne adds another layer of security to enterprises and critical industries, ensuring each private network is secure for a continuous and uninterrupted industrial ecosystem. Unauthorized use can be prevented. SIMs are only used from authorized devices. Trend Mobile Network Security also brings CT and IT security into a unified visibility and management console.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSchools can use electronic fare funds to cover Wi-Fi on buses.
Next Article How to increase WiFi speed
5gantennas.org
  • Website

Related Posts

Deutsche Telekom to operate 12,500 5G antennas over 3.6 GHz band

August 28, 2024

URCA Releases Draft “Roadmap” for 5G Rollout in the Bahamas – Eye Witness News

August 23, 2024

Smart Launches Smart ZTE Blade A75 5G » YugaTech

August 22, 2024
Leave A Reply Cancel Reply

You must be logged in to post a comment.

Latest Posts

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024

Crypto Markets Rise on Strong US Economic Data

August 29, 2024
Don't Miss

6G: Will it spark a manufacturing revolution?

By 5gantennas.orgJanuary 8, 2024

Roger Kauffman, Senior Director of Product Management and Marketing, Molex The next evolution in mobile…

Where 6G creates solid business impact

November 17, 2023

Introducing the researchers who supported the development of the 6G Framework Recommendation Draft – Samsung Global Newsroom

July 25, 2023

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to 5GAntennas.org, your reliable source for comprehensive information on 5G technology, artificial intelligence (AI), and data-related advancements. We are passionate about staying at the forefront of these cutting-edge fields and bringing you the latest insights, trends, and developments.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Most Popular

How 5G will impact entertainment

January 3, 2024

5G technology and its impact on connectivity | By Hafsa Sajjad | January 2024

January 23, 2024

Gogo updates investors on latest 5G delays

August 8, 2023
© 2025 5gantennas. Designed by 5gantennas.
  • Home
  • About us
  • Contact us
  • DMCA
  • Privacy Policy
  • About Creator

Type above and press Enter to search. Press Esc to cancel.