Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.
References
Link | Resource |
---|---|
https://tetraburst.com/ | Not Applicable |
https://tetraburst.com/ | Not Applicable |
Configurations
History
21 Nov 2024, 07:46
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-29 09:15
Updated : 2024-11-21 07:46
NVD link : CVE-2023-23773
Mitre link : CVE-2023-23773
CVE.ORG link : CVE-2023-23773
JSON object : View
Products Affected
motorola
- mbts_base_radio_firmware
- ebts_base_radio_firmware
- ebts_base_radio
- mbts_base_radio
CWE
CWE-347
Improper Verification of Cryptographic Signature