Motorola Vulnerabilities and Affected Products
Vulnerabilities associated with mtm5000_series_firmware.
Products
Clear product- Phones20 vulnerabilities
- Binatone Hubble Cameras8 vulnerabilities
- MR26005 vulnerabilities
- Mobile Radio4 vulnerabilities
- Q14 Mesh Router Firmware3 vulnerabilities
- cx2l_firmware2 vulnerabilities
- EBTS/MBTS Base Radio2 vulnerabilities
- ebts_mbts_base_radio2 vulnerabilities
- MBTS Site Controller2 vulnerabilities
- mbts_site_controller2 vulnerabilities
- MM1000 MoCA Adapter2 vulnerabilities
- MR2600 Router2 vulnerabilities
- mr2600_firmware2 vulnerabilities
- mtm5000_series_firmware2 vulnerabilities
- q14_mesh_router_firmware2 vulnerabilities
- smartphone_firmware2 vulnerabilities
- ace1000_firmware1 vulnerability
- Device Help Android App1 vulnerability
- device_help1 vulnerability
- Edge 40 Pro1 vulnerability
- Edge+ 20231 vulnerability
- firmware1 vulnerability
- g341 vulnerability
- g34t1 vulnerability
- g45 5G1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-26942HIGH | Multiple missing pointer validation checks in trusted execution module in Motorola MTM5000The Motorola MTM5000 series firmwares lack pointer validation on arguments passed to trusted execution environment (TEE) modules. Two modules are used, one responsible for KVL key management and the other for TETRA cryptographic functionality. In both modules, an adversary with non-secure supervisor level code execution can exploit the issue in order to gain secure supervisor code execution within the TEE. This constitutes a full break of the TEE module, exposing the device key as well as any TE… | CVSS8.2v3.1 | EPSS0.206% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-26943HIGH | Weak PRNG entropy source used for authentication challenge generation in Motorola MTM5000The Motorola MTM5000 series firmwares generate TETRA authentication challenges using a PRNG using a tick count register as its sole entropy source. Low boottime entropy and limited re-seeding of the pool renders the authentication challenge vulnerable to two attacks. First, due to the limited boottime pool entropy, an adversary can derive the contents of the entropy pool by an exhaustive search of possible values, based on an observed authentication challenge. Second, an adversary can use knowle… CWE-338Oct 19, 2023 | CVSS8.8v3.1 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |