An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-37242 An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.
Fixes

Solution

Motorola Solutions recommends the following for each identified vulnerability: CVE-2024-38281: * Remove the hard-coded credential to access the wireless access point and disable the access point if not needed. * Set a unique SSID and password if the access point is needed. Motorola Solutions has already remediated this vulnerability for all vulnerable systems. No further actions are required by customers.


Workaround

No workaround given by the vendor.

History

Thu, 03 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Motorola
Motorola vigilant Fixed Lpr Coms Box
Motorola vigilant Fixed Lpr Coms Box Firmware
CPEs cpe:2.3:h:motorola:vigilant_fixed_lpr_coms_box:-:*:*:*:*:*:*:*
cpe:2.3:o:motorola:vigilant_fixed_lpr_coms_box_firmware:*:*:*:*:*:*:*:*
Vendors & Products Motorola
Motorola vigilant Fixed Lpr Coms Box
Motorola vigilant Fixed Lpr Coms Box Firmware
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-02T04:04:25.256Z

Reserved: 2024-06-12T16:16:09.648Z

Link: CVE-2024-38281

cve-icon Vulnrichment

Updated: 2024-06-14T16:32:34.876Z

cve-icon NVD

Status : Modified

Published: 2024-06-13T17:15:51.607

Modified: 2024-11-21T09:25:16.470

Link: CVE-2024-38281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.