5G network security flaw exposed

Vendor exposes flaw in 5G network architecture which enables cybercriminals to attack network slices

AdaptiveMobile Security, an Irish vendor of mobile network security, has disclosed a major security flaw in 5G network slicing and virtualised network functions architectures. The vulnerability allows data access and DDoS attacks between different network slices on a mobile operator’s 5G network, exposing enterprise customers to cyberattack.

AdaptiveMobile Security examined 5G core networks that contain both shared and dedicated network functions and found that when a network has these ‘hybrid’ network functions supporting several slices there is a lack of mapping between the application and transport layer identities.

AdaptiveMobile Security uncovered three main attack scenarios based on the flaw which cannot currently be mitigated:

  • user data extraction – in particular location tracking
  • denial of service against another network function
  • access to a network function and related information of another vertical customer.

A hacker comprising an edge network function connected to the operator’s service-based architecture could exploit this flaw to gain access to both the operator’s core network and the network slices of other enterprises. Operators and their customers risk the loss of sensitive location data which would allow user location tracking, the loss of  charging-related information and even interruption to the operation of the slices and network functions themselves.

AdaptiveMobile Security says the risk level from the vulnerability is currently low because few enterprises are currently using network slicing and it is currently working with the GSMA, major operators and standards bodies to address the issue. It has produced a whitepaper detailing the issue which can be downloaded here.

Never miss a thing.

Connect your email list so you can start gathering emails. It is a great way to grow your audience into lifelong subscribers.

View more articles
  • Fraud risks: how secure is your phone number?

    Fraud risks: how secure is your phone number?

    As digital fraud in the UK remains a significant issue, Chief analyst Teresa Cottam and iconectiv’s David Wilson discuss the increasing fraud risks associated with number portability. Related posts: Transforming technology doesn't transform relationships PWC sounds the death knell of the fixed line phone business Gen Z want safety and respect The importance of empathy,…

  • 5G died at MWC23 – now we risk 6G SAG

    5G died at MWC23 – now we risk 6G SAG

    5G was killed by the hype. What hope now for 6G?

  • Brits still over-paying for handsets

    Brits still over-paying for handsets

    The most vulnerable still over-paying. More action is required by the regulator.