"value":"Transmitted data is logged between the device and the backend service. An attacker could use these logs to perform a replay attack to replicate calls."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-294 Authentication Bypass by Capture-replay",
"value":"<p>Motorola Solutions recommends the following for each identified vulnerability:</p>\n\n<p>CVE-2024-38284:</p><ul><li>Delete the log files.</li><li>Install updated software not logging the credentialed web request.</li></ul><p>Motorola Solutions has already remediated this vulnerability for all vulnerable systems. No further actions are required by customers.</p>\n\n<br>\n\n<br>"
}
],
"value":"Motorola Solutions recommends the following for each identified vulnerability:\n\n\n\nCVE-2024-38284:\n\n * Delete the log files.\n * Install updated software not logging the credentialed web request.\n\n\nMotorola Solutions has already remediated this vulnerability for all vulnerable systems. No further actions are required by customers."
}
],
"credits":[
{
"lang":"en",
"value":"The Michigan State Police Michigan Cyber Command Center (MC3)"