Malicious SIM Cards Endanger IoT Cellular Modems

Key Takeaways

  • A vulnerability in SIM cards allows malicious commands to execute on IoT devices, risking data theft and device instability.
  • Researchers from the University of Birmingham and Fuzzware identified risks in the RUN AT command, which could enable SIMs to control device functions.
  • While smartphone impact is noted, IoT devices are at greater risk, prompting recommendations for vendors to mitigate potential attacks.

New Vulnerabilities in SIM Card Technology

Researchers have discovered a vulnerability in SIM cards that enables attackers to send malicious commands to cellular modems, leading to potential code execution, data theft, and even downgrading smart devices to less secure 2G networks. The findings, presented by researchers from the University of Birmingham and Fuzzware at the USENIX WOOT conference, highlight risks associated with the RUN AT command in SIM application toolkits.

The RUN AT command allows the SIM card—a microcomputer that communicates with a device’s cellular processor—to execute AT commands autonomously. Traditionally, these commands help configure and control cellular modems, but the potential for a SIM to initiate command requests creates new security vulnerabilities. The researchers’ custom test toolkit, CATana, evaluated 26 devices, including eight IoT modems and 18 smartphones, against four attack types — code execution, denial of service, arbitrary file read, and a downgrade to the 2G network.

The tests revealed that nine of the devices supported SIM-originated AT commands, with six modems and three smartphones among them. Specific IoT devices evaluated included industrial routers, electric vehicle chargers, and automotive telematics units. Notably, SIM-originated commands sometimes reached internal application processors running Linux or Android, indicating that an attacker could exploit vulnerabilities beyond just the cellular processor.

In one demonstration, researchers successfully executed code on a modem housed in an Autel brand electric vehicle charger via a malicious SIM. Another test forced an Oppo Reno14 F 5G smartphone to downgrade to the outdated 2G standard. It is important to note that these attacks require control over the SIM through compromised software, remote access, supply-chain attacks, or physical access to the device, rather than simply knowing the phone number.

The risks associated with SIM vulnerabilities appear to be significantly greater in IoT hardware than in smartphones. Six of the eight modems examined supported the RUN AT command, compared to only three of the 18 smartphones tested. Qualcomm, which underpinned the technology in many of these devices, has announced a new default configuration that disables this interface to enhance security.

As a response to these vulnerabilities, researchers recommend that device manufacturers either deprecate support for the SIM AT interface or entirely remove related code paths, given the untrustworthiness of SIM-originated commands.

The content above is a summary. For more details, see the source article.

Leave a Comment

Your email address will not be published. Required fields are marked *

ADVERTISEMENT

Become a member

RELATED NEWS

Become a member

Scroll to Top