CVE-2024-38279

The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19 Third Party Advisory US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:motorola:vigilant_fixed_lpr_coms_box_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:vigilant_fixed_lpr_coms_box:-:*:*:*:*:*:*:*

History

21 Nov 2024, 09:25

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19 - Third Party Advisory, US Government Resource () https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19 - Third Party Advisory, US Government Resource

03 Oct 2024, 17:32

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19 - Third Party Advisory, US Government Resource
Summary
  • (es) El producto afectado es vulnerable a que un atacante modifique el gestor de arranque mediante el uso de argumentos personalizados para eludir la autenticación y obtener acceso al sistema de archivos y obtener hashes de contraseña.
CPE cpe:2.3:o:motorola:vigilant_fixed_lpr_coms_box_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:motorola:vigilant_fixed_lpr_coms_box:-:*:*:*:*:*:*:*
CWE CWE-306
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
First Time Motorola
Motorola vigilant Fixed Lpr Coms Box Firmware
Motorola vigilant Fixed Lpr Coms Box

13 Jun 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-13 17:15

Updated : 2024-11-21 09:25


NVD link : CVE-2024-38279

Mitre link : CVE-2024-38279

CVE.ORG link : CVE-2024-38279


JSON object : View

Products Affected

motorola

  • vigilant_fixed_lpr_coms_box_firmware
  • vigilant_fixed_lpr_coms_box
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel

CWE-306

Missing Authentication for Critical Function