8.8
CVSSv3

CVE-2023-23772

Published: 29/08/2023 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated malicious user to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.

Vulnerable Product Search on Vulmon Subscribe to Product

motorola mbts_site_controller_firmware r05.32.58