CVE-2023-23774
Last modified
CVE-2023-23774 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller exposes a debug prompt on the device's serial port in case of an unhandled exception. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller exposes a debug prompt on the device's serial port in case of an unhandled exception. This allows an attacker with physical access that is able to trigger such an exception to extract secret key material and/or gain arbitrary code execution on the device.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Motorola | Ebts Site Controller Firmware | All versions |
| Motorola | Mbts Site Controller Firmware | All versions |
References
- https://tetraburst.com/Not Applicable
- https://tetraburst.com/Not Applicable
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-23774?
How severe is CVE-2023-23774?
How do I fix CVE-2023-23774?
Are you affected by CVE-2023-23774?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
