logo

Widely used modems in industrial IoT devices open to SMS attack

ID: 33f9b43f-529f-520e-9889-376284706121

STIX ID: report--33f9b43f-529f-520e-9889-376284706121

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-05-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky disclosed a set of vulnerabilities in Telit Cinterion cellular modems — including a critical heap overflow (CVE-2023-47610) in SUPL handlers — that allow unauthenticated remote code execution via specially crafted SMS messages. Affected modules are widely embedded across industrial, healthcare, and telecom systems; some fixes have been issued but others remain unpatched, and mitigations include disabling SMS to devices, using private APNs, enforcing application signature checks, and preventing physical access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.