CVE-2022-30273
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-cipher in ECB mode. This mode of operation does not offer message integrity and offers reduced confidentiality above the block level, as demonstrated by an ECB Penguin attack against any block ciphers.
El protocolo MDLC de Motorola versiones hasta 02-05-2022, maneja inapropiadamente la integridad de los mensajes. Soporta tres modos de seguridad: Simple, Encriptación Legada y Nueva Encriptación. En el modo Legacy Encryption, el tráfico es cifrado por medio del cifrado en bloque Tiny Encryption Algorithm (TEA) en modo ECB. Este modo de funcionamiento no ofrece la integridad de los mensajes y ofrece una confidencialidad reducida por encima del nivel de bloque, como demuestra un ataque ECB Penguin contra cualquier cifrado de bloque.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-04 CVE Reserved
- 2022-07-26 CVE Published
- 2024-03-16 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
- CWE-345: Insufficient Verification of Data Authenticity
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation | Third Party Advisory | |
https://www.cisa.gov/uscert/ics/advisories/icsa-22-179-05 | Mitigation | |
https://www.forescout.com/blog | Not Applicable |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Motorolasolutions Search vendor "Motorolasolutions" | Mdlc Search vendor "Motorolasolutions" for product "Mdlc" | 4.80.0024 Search vendor "Motorolasolutions" for product "Mdlc" and version "4.80.0024" | - |
Affected
| ||||||
Motorolasolutions Search vendor "Motorolasolutions" | Mdlc Search vendor "Motorolasolutions" for product "Mdlc" | 4.82.004 Search vendor "Motorolasolutions" for product "Mdlc" and version "4.82.004" | - |
Affected
| ||||||
Motorolasolutions Search vendor "Motorolasolutions" | Mdlc Search vendor "Motorolasolutions" for product "Mdlc" | 4.83.001 Search vendor "Motorolasolutions" for product "Mdlc" and version "4.83.001" | - |
Affected
|