Missing Support for Integrity Check
CVE-2022-24404
Summary
Lack of cryptographic integrity check on TETRA air-interface encrypted traffic. Since a stream cipher is employed, this allows an active adversary to manipulate cleartext data in a bit-by-bit fashion.
- HIGH
- ADJACENT_NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- NONE
- LOW
CWE-353 - Missing Support for Integrity Check
The software uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum.
References
Advisory Timeline
- Published