CRITICAL🇵🇱 Wersja polska

CVE-2023-43551

CVSS 9.1v3.1pub. 2024-06-03upd. 2025-08-11

Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.

🤖 AI Analysis
How it works

During the LTE network attach procedure, the modem does not properly verify the identity of the base station before proceeding to the authentication phase. A fake base station (rogue base station) can completely bypass the authentication stage and directly send a Security Mode Command message to the modem. The modem incorrectly accepts such a command, which constitutes a bypass of the authentication mechanism (auth bypass) resulting from an error in the cryptographic implementation of the LTE protocol.

Impact

An attacker controlling a fake base station can gain unauthorized access to sensitive data transmitted by the device and manipulate the security configuration of the connection, compromising the confidentiality and integrity of communications.

Mitigation & patch

Apply patches available from the manufacturer according to references — Qualcomm security bulletin from June 2024 (https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2024-bulletin.html). OEM device manufacturers using these modems should implement firmware updates as soon as possible.

Who is affected

Firmware of Qualcomm 315 5G IoT Modem, Qualcomm 9205 LTE Modem, and Qualcomm 9206 LTE Modem — specific versions indicated in the manufacturer's security bulletin from June 2024.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Qualcomm 315 5g Iot Modem

    HW
    Qualcomm
    all versions
  • Qualcomm 315 5g Iot Modem Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm 9205 Lte Modem

    HW
    Qualcomm
    all versions
  • Qualcomm 9205 Lte Modem Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm 9206 Lte Modem

    HW
    Qualcomm
    all versions
  • Qualcomm 9206 Lte Modem Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm 9207 Lte Modem

    HW
    Qualcomm
    all versions
  • Qualcomm 9207 Lte Modem Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Apq8017

    HW
    Qualcomm
    all versions
  • Qualcomm Apq8017 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Apq8037

    HW
    Qualcomm
    all versions
  • Qualcomm Apq8037 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Aqt1000

    HW
    Qualcomm
    all versions
  • Qualcomm Aqt1000 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Ar6003

    HW
    Qualcomm
    all versions
  • Qualcomm Ar6003 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Ar8035

    HW
    Qualcomm
    all versions
  • Qualcomm Ar8035 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csra6620

    HW
    Qualcomm
    all versions
  • Qualcomm Csra6620 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csra6640

    HW
    Qualcomm
    all versions
  • Qualcomm Csra6640 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Csrb31024

    HW
    Qualcomm
    all versions
  • Qualcomm Csrb31024 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm C V2x 9150

    HW
    Qualcomm
    all versions
  • Qualcomm C V2x 9150 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6200

    HW
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6200 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6700

    HW
    Qualcomm
    all versions
  • Qualcomm Fastconnect 6700 Firmware

    OS
    Qualcomm
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-25289CRITICAL9.6PL ✓same product

Przepełnienie bufora stosu w NAN Service Discovery Frames — Qualcomm

CVE-2025-21483CRITICAL9.8PL ✓same product

Memory corruption w Qualcomm podczas składania pakietów RTP (NALUs)

CVE-2025-27034CRITICAL9.8PL ✓same product

Qualcomm Firmware — memory corruption przy wyborze PLMN z listy SOR

CVE-2025-21450CRITICAL9.1PL ✓same product

Qualcomm: podatność kryptograficzna umożliwiająca Auth Bypass podczas pobierania

CVE-2024-45569CRITICAL9.8PL ✓same product

Qualcomm: Uszkodzenie pamięci przy parsowaniu ML IE w firmware