ZeroHour

CVE-2023-23773

CVSS 3.1
8.8 high
EPSS
<1%p39
Published
()
Modified
Description

Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.

Vendors
motorola
Products
ebts base radio firmware, mbts base radio firmware
Weakness
CWE-347
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.