CVE-2019-18659
MEDIUMWireless Emergency Alerts Protocol - Presidential Alert Spoofing
Title source: manualDescription
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE System Information Block 12 (aka SIB12). NOTE: testing inside an RF-isolated shield box suggested that all LTE phones are affected by design (e.g., use of Android versus iOS does not matter); testing in an open RF environment is, of course, contraindicated.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://dl.acm.org/citation.cfm?id=3326082
Scores
CVSS v3
5.3
EPSS
0.0098
EPSS Percentile
57.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-290
Status
published
Products (1)
ready/wireless_emergency_alerts
Published
Nov 02, 2019
Tracked Since
Feb 18, 2026