{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2024-38280", "ASSIGNER": "ics-cert@hq.dhs.gov", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-313: Cleartext Storage in a File or on Disk", "cweId": "CWE-313" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "Motorola Solutions", "product": { "product_data": [ { "product_name": "Vigilant Fixed LPR Coms Box (BCAV1F2-C600)", "version": { "version_data": [ { "version_affected": "<=", "version_name": "0", "version_value": "3.1.171.9" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19", "refsource": "MISC", "name": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19" } ] }, "generator": { "engine": "Vulnogram 0.2.0" }, "source": { "discovery": "UNKNOWN" }, "solution": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\n\n
\n\n
Motorola Solutions recommends the following for each identified vulnerability:
CVE-2024-38280:
All devices shipped after May 10, 2024 are already using full disk encryption. All devices that
are not able to have full disk encryption applied have had all CJI data encrypted. No further
actions are required by customers.