The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-37240 The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.
Fixes

Solution

Motorola Solutions recommends the following for each identified vulnerability: CVE-2024-38279: * Use secure boot implementation with an edit-resistant GRUB partition. * Additional mitigation consists in limiting the physical access to the device by following the best practices for device mounting. Edit-resistant grub partition has been remediated for all vulnerable systems. Motorola Solutions will release a secure boot implementation in Fall 2024. All customers will receive the update through OTA (over the air) mechanisms. No further actions are required by customers.


Workaround

No workaround given by the vendor.

History

Thu, 03 Oct 2024 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Motorola
Motorola vigilant Fixed Lpr Coms Box
Motorola vigilant Fixed Lpr Coms Box Firmware
Weaknesses CWE-306
CPEs cpe:2.3:h:motorola:vigilant_fixed_lpr_coms_box:-:*:*:*:*:*:*:*
cpe:2.3:o:motorola:vigilant_fixed_lpr_coms_box_firmware:*:*:*:*:*:*:*:*
Vendors & Products Motorola
Motorola vigilant Fixed Lpr Coms Box
Motorola vigilant Fixed Lpr Coms Box Firmware
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-02T04:04:25.096Z

Reserved: 2024-06-12T16:16:09.648Z

Link: CVE-2024-38279

cve-icon Vulnrichment

Updated: 2024-06-13T18:29:54.745Z

cve-icon NVD

Status : Modified

Published: 2024-06-13T17:15:51.193

Modified: 2024-11-21T09:25:15.470

Link: CVE-2024-38279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.