CVE-2024-38280
MEDIUMDescription
An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| motorola | vigilant_fixed_lpr_coms_box_firmware |
| motorola | vigilant_fixed_lpr_coms_box |
References
Frequently Asked Questions
What is CVE-2024-38280? +
How severe is CVE-2024-38280? +
What products are affected by CVE-2024-38280? +
How do I check if I'm vulnerable to CVE-2024-38280? +
Related Vulnerabilities
PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's Gmail account …
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials …
A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow …
IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a …
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, …
A Cleartext Storage in a File on Disk vulnerability in Juniper Networks Junos OS Evolved ACX Series devices using the …