By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Tech NewsTech NewsTech News
Reading: Major Security Flaws in Cellular Modems Put Millions of IoT Devices at Risk
Share
Notification Show More
Font ResizerAa
Tech NewsTech News
Font ResizerAa
Follow US
© 2024 TECH.Forum | Technology News . All Rights Reserved.
Tech News > Blog > Latest Tech > Cybersecurity > Major Security Flaws in Cellular Modems Put Millions of IoT Devices at Risk
CybersecurityLatest Tech

Major Security Flaws in Cellular Modems Put Millions of IoT Devices at Risk

Nico Brams
Last updated: May 14, 2024 8:20 pm
Nico Brams 1 year ago
Share
Vulnerabilities in IoT Devices
SHARE

Overview

Millions of Internet of Things (IoT) devices across multiple industries are vulnerable to serious security threats due to flaws in a widely-used cellular modem. These devices, critical in sectors like healthcare, automotive, telecommunications, and financial services, face potential compromise from these vulnerabilities, posing significant risks.

Contents
OverviewThe VulnerabilitiesDiscovery and ReportingImpacted DevicesPotential ConsequencesMitigation MeasuresDisabling SMSPrivate APNsRole of Telecom VendorsAdditional VulnerabilitiesGrowing IoT Security ConcernsConclusionKey Points

The Vulnerabilities

The vulnerabilities, discovered in Cinterion modems made by Telit, include several severe issues:

  • Remote Code Execution Flaws: Some of these require local access for exploitation, but others can be triggered remotely.
  • Memory Heap Overflow (CVE-2023-47610): The most critical flaw allows attackers to execute arbitrary code via SMS on affected devices.

Discovery and Reporting

Kaspersky researchers identified a total of seven vulnerabilities and reported them to Telit last November. Telit has patched some, but not all, of these flaws.

Impacted Devices

Cinterion modems are integrated into IoT devices from many vendors. Examples include:

  • Industrial equipment
  • Smart meters
  • Telematics and vehicle tracking systems
  • Healthcare and medical devices

Due to their widespread use, compiling a complete list of affected devices is difficult, but potentially millions of devices are at risk.

Potential Consequences

The most severe vulnerability, CVE-2023-47610, affects a protocol for location-based services. Exploiting this flaw could allow attackers to:

  • Access the modem’s operating system
  • Manipulate device memory
  • Gain complete control over device functions

Such control could lead to unauthorized access to sensitive data, disruption of essential operations, and significant threats to public safety and security.

Mitigation Measures

Disabling SMS

Kaspersky recommends disabling all nonessential SMS capabilities on vulnerable devices. This is considered the most effective way to mitigate risks associated with CVE-2023-47610.

Private APNs

Using private Access Point Names (APNs) with strict security settings for dedicated connectivity can further protect against these vulnerabilities.

Role of Telecom Vendors

Telecom vendors are in a unique position to help prevent the delivery of malicious SMS messages to vulnerable devices, thus mitigating remote code execution risks.

Additional Vulnerabilities

The other six vulnerabilities (CVE-2023-47611 through CVE-2023-47616) relate to Java applets on the devices. These flaws can:

  • Bypass digital signature checks
  • Execute unauthorized code
  • Perform privilege escalation

Kaspersky advises enforcing rigorous digital signature verification for Java applets and conducting regular security audits and updates.

Growing IoT Security Concerns

The rising number of attacks on IoT environments, especially in industrial control and operational technology settings, is alarming. Nozomi Network’s analysis of 2023 threat data highlights an increase in IoT and OT network attacks, driven by a surge in IoT vulnerabilities. A notable example includes 11 vulnerabilities in industrial routers reported by Otorio last year, affecting thousands of industrial IoT products. Some vendors did not patch the reported vulnerabilities, exacerbating the issue.

Conclusion

The discovery of these vulnerabilities in Cinterion modems underscores the critical need for robust security measures in IoT devices. Organizations must take proactive steps to secure their devices, including disabling SMS capabilities and enforcing strict security protocols. Collaboration between device manufacturers, telecom vendors, and security researchers is essential to protect against these evolving threats.

Key Points

  • Vulnerabilities: Seven severe flaws in Cinterion modems, including remote code execution and memory heap overflow.
  • Impact: Millions of IoT devices in critical sectors at risk.
  • Mitigation: Disable nonessential SMS, use private APNs, enforce digital signature verification.
  • Industry Response: Immediate action required from device manufacturers and telecom vendors to mitigate risks.

By addressing these vulnerabilities proactively, we can safeguard the critical infrastructure that relies on these IoT devices and prevent potential security breaches.

You Might Also Like

AI Transforms iGaming: Key Trends & Effects

5G Takes to the Skies: Trial Success

Augmented Reality: Boosting Efficiency

CrowdStrike Update Triggers Major Global Outage

Steve Blank on AI: Strategy for Startups

TAGGED: IoT, Security Flaws, Vulnerabilities
Share This Article
Facebook Twitter LinkedIn Email
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Tackling Data Security Challenges in Modern Organizations
Next Article Navigating Data Privacy: Key Issues and How to Overcome Them
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

Italian Companies Lead the Way in Sustainable Governance
Sustainability
Brazil’s G20 Leadership: A Chance to Boost Public Health and Decolonise Global Health
Global & EU Policies World & Europe
Why Speeding Up Support for Article 6.2 of the Paris Agreement Matters
Global & EU Policies World & Europe
Embracing Sustainable Wellness: Eco-Friendly Practices for a Healthier Life
Sustainability

Most Viewed Posts

  • OpenAI Launches New AI Model GPT-4o with Realistic Voice Capabilities
  • EU Sets New Standards for Election Integrity: A Guide for Social Media Titans Under the Digital Services Act
  • How Secure Are Your Digital Footprints?
  • Sustainable Practices and Goals at Largest Companies like Amazon, Google, and Apple
  • Renewables Reach Record Levels: Powering More than a Third of the Globe
about us

Tech.forum News is Europe's premier source of technology related news, gathered from all over the globe on a single platform to fulfill your yearning for the latest updates on technology

Find Us on Socials

© Copyright | Tech.Forum News. All Rights Reserved.
Welcome Back!

Sign in to your account

Lost your password?