Lucene search

K
cveIcscertCVE-2024-38280
HistoryJun 13, 2024 - 5:15 p.m.

CVE-2024-38280

2024-06-1317:15:51
CWE-313
icscert
web.nvd.nist.gov
23
cve-2024-38280
cleartext storage
unauthorized access
sensitive data
credentials
physical retrieval

CVSS4

7

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

9.0%

An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Vigilant Fixed LPR Coms Box (BCAV1F2-C600)",
    "vendor": "Motorola Solutions",
    "versions": [
      {
        "lessThanOrEqual": "3.1.171.9",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS4

7

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

9.0%

Related for CVE-2024-38280