{"id":41852,"date":"2020-12-18T03:04:56","date_gmt":"2020-12-18T11:04:56","guid":{"rendered":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/gsma_resources\/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication\/"},"modified":"2020-12-18T03:04:56","modified_gmt":"2020-12-18T11:04:56","slug":"vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication","status":"publish","type":"gsma_theme_resources","link":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/gsma_resources\/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication\/","title":{"rendered":"Vulnerabilities in Standalone 5G networks could allow attackers to steal credentials and falsify subscriber authentication"},"content":{"rendered":"<p>December 16, 2020:\u00a0<a href=\"https:\/\/hubs.la\/H0CNsNl0\" target=\"_blank\" rel=\"noopener noreferrer\">Positive Technologies<\/a>\u00a0has published its \u201c<a href=\"https:\/\/hubs.la\/H0CNmC30\" target=\"_blank\" rel=\"noopener noreferrer\"><em>5G standalone core security assessment<\/em><\/a><em>\u201d.\u00a0<\/em>The report discusses vulnerabilities and threats for subscribers and mobile network operators, which stem from the use of new standalone 5G network cores. The vulnerabilities in protocols HTTP\/2 and PFCP, used by standalone 5G networks, include the theft of subscriber profile data, impersonation attacks and faking subscriber authentication.<\/p>\n<p>Mobile operators are currently running non-standalone 5G networks, which are based on previous-generation 4G LTE infrastructure. These non-standalone 5G networks are at risk of attack\u00a0<a href=\"https:\/\/positive-tech.com\/knowledge-base\/research\/gtp-2020\/\" target=\"_blank\" rel=\"noopener noreferrer\">because of long-standing vulnerabilities in the Diameter and GTP protocols<\/a>, which were reported on by Positive Technologies earlier this year. Operators are gradually migrating to standalone infrastructure, but this also has security considerations of its own.\u00a0<a href=\"https:\/\/www.computerweekly.com\/news\/252486769\/Global-telco-5G-network-infrastructure-spending-set-to-almost-double-in-2020\" target=\"_blank\" rel=\"noopener noreferrer\">Gartner<\/a>\u00a0expects 5G investment to exceed LTE\/4G in 2022 and that communications service providers will gradually add standalone capabilities to their\u00a0<a href=\"https:\/\/www.computerweekly.com\/news\/252478950\/KDDI-taps-Nokia-Ericsson-for-5G-standalone-network-technology\" target=\"_blank\" rel=\"noopener noreferrer\">non-standalone 5G networks<\/a>.<\/p>\n<p>The stack of technologies in 5G potentially leaves the door open to attacks on subscribers and the operator&#8217;s network. Such attacks can be performed from the international roaming network, the operator&#8217;s network, or partner networks that provide access to services.<\/p>\n<p>For example, the Packet Forwarding Control Protocol (PFCP) that is used to make subscriber connections has several potential vulnerabilities such as denial of service, cutting subscriber access to the internet and redirecting traffic to an attacker, allowing them to downlink the data of a subscriber. Correct configuration of the architecture as highlighted in Positive Technologies\u00a0<a href=\"https:\/\/hubs.la\/H0CNmBS0\" target=\"_blank\" rel=\"noopener noreferrer\">GTP protocol research<\/a>\u00a0can stop these types of attacks.<\/p>\n<p>The HTTP\/2 protocol, which is responsible for vital network functions (NFs) that register and store profiles on 5G networks, also contains several vulnerabilities. Using these vulnerabilities, attackers could obtain the NF profile and impersonate any network service using details such as authentication status, current location, and subscriber settings for network access. Attackers can also delete NF profiles potentially causing financial losses and damaging subscriber trust.<\/p>\n<p>In these cases, subscribers will be unable to take action against threats that lurk on the network, so operators need to have sufficient visibility to safeguard against these attacks.<\/p>\n<p><strong>Dmitry Kurbatov, CTO at Positive Technologies commented:\u00a0<\/strong>\u201cThere is a risk that attackers will take advantage of standalone 5G networks while they are being established and operators are getting to grips with potential vulnerabilities. Therefore, security considerations must be addressed by operators from the offset. Subscriber attacks can be both financially and reputationally damaging &#8211; especially when vendors are in high competition to launch their 5G networks. With such a diverse surface of attack, robust core network security architecture is by far the safest way to protect users.<\/p>\n<p>\u201c5G standalone network security issues will be much further reaching when it comes to CNI, IoT and connected cities &#8211; putting critical infrastructure such as hospitals, transport and utilities at risk. In order to achieve full visibility over traffic and messaging, operators need to perform regular security audits to detect errors in the configuration of network core components to protect themselves and their subscribers\u201d<\/p>\n<p>For more information on vulnerabilities of standalone 5G networks, download the full report\u00a0<a href=\"https:\/\/hubs.la\/H0CNmC30\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Positive Technologies\u00a0has published its \u201c5G standalone core security assessment\u201d.\u00a0The report discusses vulnerabilities and threats for subscribers and mobile network operators, which stem from the use of new standalone 5G network cores.<\/p>\n","protected":false},"author":2,"featured_media":0,"template":"","meta":{"image":null,"json":{"gsma_resources_type":"Press Release","gsma_resources_thumb":"[]","gsma_resources_file":"[]","gsma_resources_multi":null,"gsma_resources_wgr":null,"gsma_resources_video":null,"gsma_resources_image":"[]","gsma_resources_url":null,"gsma_resources_date":"16\/12\/2020","gsma_resources_button":"Download"}},"tags":[],"resource_categories":[4871],"algolia_discover_type":[9668],"class_list":["post-41852","gsma_theme_resources","type-gsma_theme_resources","status-publish","hentry","resource_categories-member-press-release","algolia_discover_type-resource"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.9 (Yoast SEO v24.4) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Vulnerabilities in Standalone 5G networks could allow attackers to steal credentials and falsify subscriber authentication - Membership<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/gsma_resources\/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vulnerabilities in Standalone 5G networks could allow attackers to steal credentials and falsify subscriber authentication\" \/>\n<meta property=\"og:description\" content=\"Positive Technologies\u00a0has published its \u201c5G standalone core security assessment\u201d.\u00a0The report discusses vulnerabilities and threats for subscribers and mobile network operators, which stem from the use of new standalone 5G network cores.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/gsma_resources\/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication\/\" \/>\n<meta property=\"og:site_name\" content=\"Membership\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@gsma\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Vulnerabilities in Standalone 5G networks could allow attackers to steal credentials and falsify subscriber authentication - Membership","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/gsma_resources\/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication\/","og_locale":"en_US","og_type":"article","og_title":"Vulnerabilities in Standalone 5G networks could allow attackers to steal credentials and falsify subscriber authentication","og_description":"Positive Technologies\u00a0has published its \u201c5G standalone core security assessment\u201d.\u00a0The report discusses vulnerabilities and threats for subscribers and mobile network operators, which stem from the use of new standalone 5G network cores.","og_url":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/gsma_resources\/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication\/","og_site_name":"Membership","twitter_card":"summary_large_image","twitter_site":"@gsma","twitter_misc":{"Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/gsma_resources\/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication\/","url":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/gsma_resources\/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication\/","name":"Vulnerabilities in Standalone 5G networks could allow attackers to steal credentials and falsify subscriber authentication - Membership","isPartOf":{"@id":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/#website"},"datePublished":"2020-12-18T11:04:56+00:00","breadcrumb":{"@id":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/gsma_resources\/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.gsma.com\/get-involved\/gsma-membership\/gsma_resources\/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/gsma_resources\/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/"},{"@type":"ListItem","position":2,"name":"Vulnerabilities in Standalone 5G networks could allow attackers to steal credentials and falsify subscriber authentication"}]},{"@type":"WebSite","@id":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/#website","url":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/","name":"GSMA Membership","description":"","publisher":{"@id":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/#organization","name":"GSMA","url":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/#\/schema\/logo\/image\/","url":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/wp-content\/uploads\/2023\/10\/GSMA-Logo-Red-RGB.png","contentUrl":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/wp-content\/uploads\/2023\/10\/GSMA-Logo-Red-RGB.png","width":8001,"height":1255,"caption":"GSMA"},"image":{"@id":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/gsma"]}]}},"cats":[{"term_id":9670,"name":"Member Blog and Articles","slug":"blog","term_group":0,"term_taxonomy_id":9670,"taxonomy":"resource_categories","description":"GSMAs' Member Blog and Articles","parent":0,"count":80,"filter":"raw"},{"term_id":5257,"name":"Member Case Study","slug":"case-study","term_group":0,"term_taxonomy_id":5257,"taxonomy":"resource_categories","description":"GSMA Members\u2019 Case Studies","parent":0,"count":9,"filter":"raw"},{"term_id":4871,"name":"Member Press Release","slug":"member-press-release","term_group":0,"term_taxonomy_id":4871,"taxonomy":"resource_categories","description":"GSMA Members' Press Release","parent":0,"count":1081,"filter":"raw"},{"term_id":4872,"name":"Resources and Documentation","slug":"resource-document","term_group":0,"term_taxonomy_id":4872,"taxonomy":"resource_categories","description":"GSMA Members\u2019 White Paper","parent":0,"count":42,"filter":"raw"}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/wp-json\/wp\/v2\/gsma_theme_resources\/41852"}],"collection":[{"href":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/wp-json\/wp\/v2\/gsma_theme_resources"}],"about":[{"href":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/wp-json\/wp\/v2\/types\/gsma_theme_resources"}],"author":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/wp-json\/wp\/v2\/users\/2"}],"version-history":[{"count":0,"href":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/wp-json\/wp\/v2\/gsma_theme_resources\/41852\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/wp-json\/wp\/v2\/media?parent=41852"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/wp-json\/wp\/v2\/tags?post=41852"},{"taxonomy":"resource_categories","embeddable":true,"href":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/wp-json\/wp\/v2\/resource_categories?post=41852"},{"taxonomy":"algolia_discover_type","embeddable":true,"href":"https:\/\/www.gsma.com\/get-involved\/gsma-membership\/wp-json\/wp\/v2\/algolia_discover_type?post=41852"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}