CAPEC 618 Cellular Broadcast Message Request

Draft Detailed Unknown Risk
Severity Low

Description

In this attack scenario, the attacker uses knowledge of the target\u00e2\u0080\u0099s mobile phone number (i.e., the number associated with the SIM used in the retransmission device) to cause the cellular network to send broadcast messages to alert the mobile device. Since the network knows which cell tower the target\u00e2\u0080\u0099s mobile device is attached to, the broadcast messages are only sent in the Location Area Code (LAC) where the target is currently located. By triggering the cellular broadcast message and then listening for the presence or absence of that message, an attacker could verify that the target is in (or not in) a given location.

Mitigations

1

Consequences

Relationships