Multiple missing pointer validation checks in trusted execution module in Motorola MTM5000
CVE-2022-26942
8.2HIGH
What is CVE-2022-26942?
The Motorola MTM5000 series firmware contains a significant vulnerability due to insufficient pointer validation in trusted execution environment (TEE) modules. Specifically, the KVL key management and TETRA cryptographic functionality modules are affected. An attacker with the ability to execute non-secure supervisor level code can exploit this weakness to gain unauthorized secure supervisor code execution within the TEE. This breach leads to a complete compromise of the TEE module, resulting in unauthorized access to the device's cryptographic keys, including TETRA keys and confidential cryptographic primitives.
Affected Version(s)
Mobile Radio MTM5000