Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-23772

CVSS 7.2 · High EPSS 0.03% · P8
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-23772

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
密码学签名的验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Motorola MBTS Site Controller 数据伪造问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Motorola MBTS Site Controller是美国摩托罗拉(Motorola)公司的一种设备,用于管理和控制无线通信基站(Macro Base Transceiver Station,MBTS)以及与其相关的功能。 Motorola MBTS Site Controller存在安全漏洞,该漏洞源于无法检查固件更新的真实性,允许经过身份验证的攻击者执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
MotorolaMBTS Site Controller R05.32.58 -

II. Public POCs for CVE-2023-23772

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-23772

登录查看更多情报信息。

Same Patch Batch · Motorola · 2023-08-29 · 5 CVEs total

CVE-2023-237709.4 CRITICALMotorola MBTS Site Controller 信任管理问题漏洞
CVE-2023-237748.4 HIGHMotorola MBTS Site Controller 安全漏洞
CVE-2023-237718.4 HIGHMotorola MBTS Base Radio 信任管理问题漏洞
CVE-2023-237737.2 HIGHMotorola MBTS Base Radio和Motorola EBTS Base Radio 数据伪造问题漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2023-23772

No comments yet


Leave a comment