“…[67], [68], [69] U V-A1 TMSI Deanonymization (Paging Attack) [4], [5], [86] U V-A1 Cell-Level Tracking with SS7/MAP [56] U V-D1 GPS Location with SS7/LCS [56] U V-D1 Integrity ASN.1 Heap Overflow [87] U,P VI-A1 Binary Baseband Exploit [11], [88], [89] U VI-A1 SMS Parsing [90], [91] U VI-A1 SIM Card Rooting [85] U VI-A1 Fraud Fake Base Station SMS Spam [92], [93] U V-B1 LTE IMS-based SMS Spoofing [83], [94] U VII-A1 Misbilling: TCP Retransmission or DNS Tunneling [95], [95], [96] P VII-B1 Underbilling using VoLTE Hidden Channels [97], [98] P VII-B1 Uplink IP Header Spoofing/Cloak-and-Dagger Misbilling [28], [99] U VII-A1 Unblock Stolen Devices [100] U V-D1 yes, applicable, needed for attack partially/supportive/optional no, not applicable, or does not apply ? property unknown not depend on a specification and can be implemented directly into network components.…”