Detailedseverity: LowDraft

CAPEC-618Cellular Broadcast Message Request

Abstraction
Detailed
Status
Draft
Severity
Low

Description

In this attack scenario, the attacker uses knowledge of the target’s mobile phone number (i.e., the number associated with the SIM used in the retransmission device) to cause the cellular network to send broadcast messages to alert the mobile device. Since the network knows which cell tower the target’s mobile device is attached to, the broadcast messages are only sent in the Location Area Code (LAC) where the target is currently located. By triggering the cellular broadcast message and then listening for the presence or absence of that message, an attacker could verify that the target is in (or not in) a given location.

Related weaknesses· 1

CWE-201

Related attack patterns· 1

CAPEC-292 (ChildOf)

Exploits1

TypeTargetConfidenceTier
WeaknessInsertion of Sensitive Information Into Sent Datacwe-201100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Signal Strength Tracking
CAPEC
Cellular Rogue Base Station
CAPEC
Cellular Traffic Intercept
CAPEC
Cellular Jamming
CAPEC
Cellular Data Injection
CAPEC
Mobile Phishing
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.