Vulnerability Description
The Motorola MTM5000 series firmwares generate TETRA authentication challenges using a PRNG using a tick count register as its sole entropy source. Low boottime entropy and limited re-seeding of the pool renders the authentication challenge vulnerable to two attacks. First, due to the limited boottime pool entropy, an adversary can derive the contents of the entropy pool by an exhaustive search of possible values, based on an observed authentication challenge. Second, an adversary can use knowledge of the entropy pool to predict authentication challenges. As such, the unit is vulnerable to CVE-2022-24400.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Motorola | Mtm5500 Firmware | - |
| Motorola | Mtm5500 | - |
| Motorola | Mtm5400 Firmware | - |
| Motorola | Mtm5400 | - |
Related Weaknesses (CWE)
References
- https://tetraburst.com/Technical Description
- https://tetraburst.com/Technical Description
FAQ
What is CVE-2022-26943?
CVE-2022-26943 is a vulnerability with a CVSS score of 8.8 (HIGH). The Motorola MTM5000 series firmwares generate TETRA authentication challenges using a PRNG using a tick count register as its sole entropy source. Low boottime entropy and limited re-seeding of the p...
How severe is CVE-2022-26943?
CVE-2022-26943 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-26943?
Check the references section above for vendor advisories and patch information. Affected products include: Motorola Mtm5500 Firmware, Motorola Mtm5500, Motorola Mtm5400 Firmware, Motorola Mtm5400.