Researchers have reported the discovery of 84 previously unknown vulnerabilities affecting the core networks of 4G and 5G mobile systems. These flaws, collectively termed 'iTrue' vulnerabilities, are described as stemming from implicit trust errors between various network functions within the core infrastructure. The report indicates that these issues could potentially be exploited to facilitate denial-of-service attacks and session hijacking.
The technical mechanism behind these 'iTrue' flaws is rooted in scenarios where network functions implicitly trust each other without sufficient validation or authentication. This implicit trust, when exploited, allows an attacker to bypass security controls by masquerading as a legitimate network component or by manipulating trusted communication paths. The shift towards cloud-native deployments in 4G and 5G core networks is cited as a factor that exacerbates these vulnerabilities, likely due to the increased complexity and dynamic nature of inter-service communication in such environments.
One of the most significant potential impacts highlighted is session hijacking. In a session hijacking scenario, an attacker could seize control of a legitimate user's network session. This could grant the attacker unauthorized access to services or data associated with that session, potentially leading to privacy breaches, unauthorized transactions, or further network compromise. Denial-of-service attacks are also a reported risk, where an attacker could disrupt network availability or specific services by overwhelming or disabling critical core network functions.
While specific vendors or products were not named, these vulnerabilities affect the core networks of both 4G and 5G mobile systems. This implies that the issues are likely present in the implementations of various network equipment providers and telecommunication operators globally, given the widespread adoption of these standards. The scope could therefore be broad, impacting a significant portion of the global mobile subscriber base if exploited.
Mitigation for this class of implicit trust errors typically involves implementing robust authentication and authorization mechanisms between all network functions, even those considered internal or trusted. This includes mutual authentication, stricter input validation, and comprehensive integrity checks for all inter-component communications. Network segmentation and micro-segmentation can also limit the blast radius of an exploit, preventing an attacker from easily moving laterally across the core network. Regular security audits and penetration testing focused on inter-service communication flows are also crucial for identifying and remediating such vulnerabilities.
The discovery of these 'iTrue' vulnerabilities underscores the ongoing security challenges inherent in complex, interconnected network infrastructures, particularly as they evolve towards cloud-native architectures. As mobile networks become increasingly critical for a wide array of services, from personal communication to industrial IoT, the security of their core components remains paramount. This report highlights the continuous need for rigorous security research and proactive measures to secure the foundational elements of global telecommunications.






