CVE-2023-23773
Last modified
CVE-2023-23773 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Motorola | Ebts Base Radio Firmware | r05.x2.57 |
| Motorola | Mbts Base Radio Firmware | r05.x2.57 |
References
- https://tetraburst.com/Not Applicable
- https://tetraburst.com/Not Applicable
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-23773?
How severe is CVE-2023-23773?
How do I fix CVE-2023-23773?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-23766An incorrect comparison vulnerability was identified in GitH…6.5
- CVE-2023-23767Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-2377A vulnerability was detected in Ubiquiti EdgeRouter X up to …7.2
- CVE-2023-23770Motorola MBTS Site Controller accepts hard-coded backdoor pa…9.8
- CVE-2023-23771Motorola MBTS Base Radio accepts hard-coded backdoor passwor…8.4
- CVE-2023-23772Motorola MBTS Site Controller fails to check firmware update…8.8
- CVE-2023-23774Motorola EBTS/MBTS Site Controller drops to debug prompt on …8.4
- CVE-2023-23775Multiple improper neutralization of special elements used in…8.8
- CVE-2023-23776An exposure of sensitive information to an unauthorized acto…3.1
- CVE-2023-23777An improper neutralization of special elements used in an OS…7.2
- CVE-2023-23778A relative path traversal vulnerability [CWE-23] in FortiWeb…6.5
- CVE-2023-23779Multiple improper neutralization of special elements used in…8.8
Are you affected by CVE-2023-23773?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
