CVE-2024-38279

The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19 Third Party Advisory US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:motorola:vigilant_fixed_lpr_coms_box_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:vigilant_fixed_lpr_coms_box:-:*:*:*:*:*:*:*

History

21 Nov 2024, 09:25

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19 - Third Party Advisory, US Government Resource () https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19 - Third Party Advisory, US Government Resource

03 Oct 2024, 17:32

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19 - Third Party Advisory, US Government Resource
CWE CWE-306
First Time Motorola vigilant Fixed Lpr Coms Box
Motorola
Motorola vigilant Fixed Lpr Coms Box Firmware
Summary
  • (es) El producto afectado es vulnerable a que un atacante modifique el gestor de arranque mediante el uso de argumentos personalizados para eludir la autenticación y obtener acceso al sistema de archivos y obtener hashes de contraseña.
CPE cpe:2.3:h:motorola:vigilant_fixed_lpr_coms_box:-:*:*:*:*:*:*:*
cpe:2.3:o:motorola:vigilant_fixed_lpr_coms_box_firmware:*:*:*:*:*:*:*:*

13 Jun 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-13 17:15

Updated : 2024-11-21 09:25


NVD link : CVE-2024-38279

Mitre link : CVE-2024-38279

CVE.ORG link : CVE-2024-38279


JSON object : View

Products Affected

motorola

  • vigilant_fixed_lpr_coms_box_firmware
  • vigilant_fixed_lpr_coms_box
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel

CWE-306

Missing Authentication for Critical Function