Firmware Update Vulnerability in Motorola MBTS Site Controller
CVE-2023-23772

7.2HIGH

Key Information:

Vendor
Motorola
Vendor
CVE Published:
29 August 2023

Summary

The Motorola MBTS Site Controller suffers from a significant vulnerability due to its failure to validate the authenticity of firmware updates. This flaw enables an authenticated attacker to bypass security measures, potentially leading to arbitrary code execution on the device. Moreover, the lack of cryptographic signature validation poses an increased risk, allowing attackers to extract sensitive key material or implant persistent malware. Organizations using this device should immediately assess their security posture to mitigate potential exploitation.

Affected Version(s)

MBTS Site Controller R05.32.58

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Midnight Blue
.