Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-23772


Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.


Published

2023-08-29T09:15:09.193

Last Modified

2024-11-21T07:46:47.970

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-347
  • Type: Primary
    CWE-347

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System motorola mbts_site_controller_firmware r05.32.58 Yes
Hardware motorola mbts_site_controller - No

References