Lucene search

K
cvelistIcscertCVELIST:CVE-2024-38280
HistoryJun 13, 2024 - 5:05 p.m.

CVE-2024-38280 Cleartext Storage in a File or on Disk in Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600)

2024-06-1317:05:58
CWE-313
icscert
www.cve.org
4
cleartext storage
vulnerability
motorola solutions vigilant
fixed lpr coms box
data breach
sensitive data
unauthorized access

CVSS4

7

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N

EPSS

0

Percentile

9.0%

An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Vigilant Fixed LPR Coms Box (BCAV1F2-C600)",
    "vendor": "Motorola Solutions",
    "versions": [
      {
        "lessThanOrEqual": "3.1.171.9",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS4

7

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N

EPSS

0

Percentile

9.0%

Related for CVELIST:CVE-2024-38280