NIST SP 800-127 Draft

Unilateral Authentication - An IEEE 802.16-2004 vulnerability resulting from PKMv1 providing for authentication of SSs by BSs but not for authentication of BSs by SSs. Lack of mutual authentication may allow a rogue BS to impersonate a legitimate BS, thereby rendering the SS unable to verify the authenticity of protocol messages received from the BS. This may enable a rogue BS operator to degrade performance or steal valuable information by conducting DoS or man-in-the-middle attacks against client SSs.