> How hard are these attacks to actually execute?
Fake roaming request, and that's it.
> Can someone with an SDR and no credentials start an attack?
No, but any telco employee in the world with keys to the server room can.
The matter is SS7 vulnerabilities are not Man-in-the-Middle in nature, but Man-on-the-Other-Side-of-the-World in nature.