Vulnerability Description
The TETRA TA61 identity encryption function internally uses a 64-bit value derived exclusively from the SCK (Class 2 networks) or CCK (Class 3 networks). The structure of TA61 allows for efficient recovery of this 64-bit value, allowing an adversary to encrypt or decrypt arbitrary identities given only three known encrypted/unencrypted identity pairs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Midnightblue | Tetra\ | burst |
Related Weaknesses (CWE)
References
- https://tetraburst.com/Third Party Advisory
- https://tetraburst.com/Third Party Advisory
FAQ
What is CVE-2022-24403?
CVE-2022-24403 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The TETRA TA61 identity encryption function internally uses a 64-bit value derived exclusively from the SCK (Class 2 networks) or CCK (Class 3 networks). The structure of TA61 allows for efficient rec...
How severe is CVE-2022-24403?
CVE-2022-24403 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24403?
Check the references section above for vendor advisories and patch information. Affected products include: Midnightblue Tetra\.