Site icon Auspreneur

Dutch Researchers Reveal Critical Vulnerabilities in TETRA Radio Protocol

Security researchers from Midnight Blue have disclosed a set of vulnerabilities, known as TETRA.BURST, in the TETRA protocol widely used by emergency services, military, infrastructure, and other applications.

These cryptographic flaws include real-time decryption, message injection, user deanonymization, and session key pinning, among others. The vulnerabilities, labeled CVE-2022-24401, CVE-2022-24402, CVE-2022-24404, CVE-2022-24403, and CVE-2022-24400, affect TETRA networks, potentially compromising their security.

Most vendors have begun shipping firmware patches to address the vulnerabilities, but some may require additional mitigations using compensating controls.

CVE-2022-22401 is a critical vulnerability enabling decryption oracle attacks due to TETRA’s air interface encryption keystream relying on publicly broadcast unauthenticated network time. This flaw could allow adversaries to intercept and manipulate law enforcement and military radio communications.

CVE-2022-22402 is another critical flaw, revealing a backdoor in TETRA’s TEA1 algorithm, reducing the original 80-bit key to a size that can be easily brute-forced on consumer hardware. This leads to a complete break of the cipher, permitting interception and manipulation of radio traffic.

Other high-severity vulnerabilities include CVE-2022-24403 (user deanonymisation) and CVE-2022-24404 (lack of ciphertext authentication on the air interface). A low-severity flaw is also present, identified as CVE-2022-24400, affecting the authentication algorithm.

Firmware patches are available for some vulnerabilities, while end-to-end encryption can mitigate others. Migrating to TAA2 fixes CVE-2022-24400.

Exit mobile version