CVE-2022-27813

Motorola MTM5000 series firmwares lack properly configured memory protection of pages shared between the OMAP-L138 ARM and DSP cores. The SoC provides two memory protection units, MPU1 and MPU2, to enforce the trust boundary between the two cores. Since both units are left unconfigured by the firmwares, an adversary with control over either core can trivially gain code execution on the other, by overwriting code located in shared RAM or DDR2 memory regions.
References
Link Resource
https://tetraburst.com/ Technical Description
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:motorola:mtm5500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:motorola:mtm5500:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:motorola:mtm5400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:motorola:mtm5400:-:*:*:*:*:*:*:*

History

27 Oct 2023, 21:53

Type Values Removed Values Added
References (MISC) https://tetraburst.com/ - (MISC) https://tetraburst.com/ - Technical Description
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.2
CPE cpe:2.3:o:motorola:mtm5400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:motorola:mtm5500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:motorola:mtm5500:-:*:*:*:*:*:*:*
cpe:2.3:h:motorola:mtm5400:-:*:*:*:*:*:*:*
First Time Motorola mtm5400
Motorola mtm5500
Motorola mtm5400 Firmware
Motorola
Motorola mtm5500 Firmware

19 Oct 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-19 10:15

Updated : 2023-12-10 15:14


NVD link : CVE-2022-27813

Mitre link : CVE-2022-27813

CVE.ORG link : CVE-2022-27813


JSON object : View

Products Affected

motorola

  • mtm5400_firmware
  • mtm5500_firmware
  • mtm5400
  • mtm5500
CWE
NVD-CWE-noinfo CWE-1260

Improper Handling of Overlap Between Protected Memory Ranges