Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-23774


Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller exposes a debug prompt on the device's serial port in case of an unhandled exception. This allows an attacker with physical access that is able to trigger such an exception to extract secret key material and/or gain arbitrary code execution on the device.


Published

2023-08-29T09:15:09.403

Last Modified

2024-11-21T07:46:48.237

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.4 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-248
  • Type: Primary
    CWE-755

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System motorola ebts_site_controller_firmware - Yes
Hardware motorola ebts_site_controller - No
Operating System motorola mbts_site_controller_firmware - Yes
Hardware motorola mbts_site_controller - No

References