Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-23773


Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.


Published

2023-08-29T09:15:09.330

Last Modified

2024-11-21T07:46:48.100

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-347
  • Type: Primary
    CWE-347

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System motorola ebts_base_radio_firmware r05.x2.57 Yes
Hardware motorola ebts_base_radio - No
Operating System motorola mbts_base_radio_firmware r05.x2.57 Yes
Hardware motorola mbts_base_radio - No

References