CVE-2022-24403

MEDIUM

midnightblue tetra - Use of a Broken or Risky Cryptographic Algorithm in TA61 Identity Encryption

Title source: llm
STIX 2.1

Description

The TETRA TA61 identity encryption function internally uses a 64-bit value derived exclusively from the SCK (Class 2 networks) or CCK (Class 3 networks). The structure of TA61 allows for efficient recovery of this 64-bit value, allowing an adversary to encrypt or decrypt arbitrary identities given only three known encrypted/unencrypted identity pairs.

References (1)

Core 1
Core References
Third Party Advisory related
https://tetraburst.com/

Scores

CVSS v3 4.3
EPSS 0.0011
EPSS Percentile 1.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-327
Status published
Products (1)
midnightblue/tetra\ burst
Published Dec 05, 2023
Tracked Since Feb 18, 2026