CVE-2022-24402: high-severity vulnerability in ETSI TETRA Standard
Intentionally weakened effective strength in TETRA TEA1
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
TETRA TEA1 encryption reduces an 80-bit key to just 32 bits during operation, making it vulnerable to brute-force attacks that can crack the encryption in reasonable time.
The TEA1 keystream generator's key register initialization compresses the full 80-bit key material to 32 bits effective entropy for keystream generation, enabling exhaustive search attacks with feasible computational cost. This design weakness significantly reduces the cryptographic strength below the theoretical key size, allowing attackers to recover the keystream through key enumeration.
In the same product, most dangerous first.