* 3G has no integrity protection. Downgrade attacks from 3G->2G work. Also, it's the base station who decides if authentication and encryption is done. Fake base stations can still be used to track location, intercept calls and data.
* LTE/4G has mutual authentication and mandatory integrity protection. In theory you can't get IMEI if the message has no integrity but the protocols are not perfect.
LTE/4G can still be intercepted by using jammers, DoS attacks or exploiting weaknesses in the protocols and implementations to force a downgrade. Some messages in the protocols still go unencrypted and without authentication. It's for example possible to edit voice domain preference or send "LTE services not allowed" messages or edit the list of supported protocols to force downgrade.
Practical attacks against privacy and availability in 4G/LTE mobile communication systems https://arxiv.org/pdf/1510.07563v1.pdf