Widely used Telit Cinterion modems open to SMS takeover attacks
ID: 3bd2ee6e-3910-50a4-b1ae-0284b4f6b558
STIX ID: report--3bd2ee6e-3910-50a4-b1ae-0284b4f6b558
Feed Name: Bleeping Computer
Kaspersky ICS CERT disclosed eight vulnerabilities in Telit Cinterion cellular modems—most critically CVE-2023-47610, a heap overflow in SUPL message handlers allowing unauthenticated, remote code execution via specially crafted SMS. The flaws affect multiple widely deployed Cinterion models embedded in industrial, healthcare, and telecom equipment, can enable deep modem compromise (RAM/flash manipulation and manufacturer-level code execution), and although some fixes were issued, several vulnerabilities remain unpatched; Kaspersky recommends telecom operator mitigations (disable SMS to devices, private APN) and enforcing application signature verification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
