PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-38280 Motorola Solutions CVE debrief

Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600) stores sensitive data, including credentials, in clear text on the hard disk. An unauthorized user with physical access can retrieve the hard disk and gain access to this sensitive data. The vulnerability affects devices running firmware version 3.1.171.9 and earlier. Motorola Solutions has addressed this by implementing full disk encryption using LUKS standards and GRUB Bootloader password protection on devices shipped after May 10, 2024. For devices unable to receive full disk encryption, all Criminal Justice Information (CJI) data has been encrypted. The CVSS 3.1 score of 6.8 reflects the physical attack vector required, with high impacts to confidentiality, integrity, and availability once access is obtained.

Vendor
Motorola Solutions
Product
Vigilant Fixed LPR Coms Box (BCAV1F2-C600)
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-13
Original CVE updated
2024-06-13
Advisory published
2024-06-13
Advisory updated
2024-06-13

Who should care

Organizations operating Motorola Solutions Vigilant Fixed LPR Coms Box systems, particularly law enforcement and government agencies handling Criminal Justice Information (CJI) subject to CJIS Security Policy requirements. Security teams responsible for physical security of traffic infrastructure and automated license plate recognition deployments.

Technical summary

The Vigilant Fixed LPR Coms Box stores sensitive authentication credentials and Criminal Justice Information (CJI) in unencrypted form on the local hard disk. This allows an attacker with physical access to remove the storage device and extract sensitive data without authentication. The vulnerability is classified as medium severity (CVSS 3.1: 6.8) due to the physical attack vector requirement, though impact is rated high across confidentiality, integrity, and availability dimensions. Remediation requires cryptographic controls: full disk encryption per LUKS standards, bootloader password protection, and column-level database encryption for sensitive fields.

Defensive priority

high

Recommended defensive actions

  • Apply full disk encryption using LUKS standards with GRUB Bootloader password protection to all affected devices
  • Implement column-level encryption for sensitive database data containing Criminal Justice Information (CJI)
  • Verify all devices shipped after May 10, 2024 have encryption enabled; no further action required for these units
  • For devices that cannot support full disk encryption, ensure all CJI data is encrypted at the application or database level
  • Restrict physical access to LPR Coms Box hardware to authorized personnel only
  • Audit existing deployments to identify devices running firmware version 3.1.171.9 or earlier requiring remediation

Evidence notes

CISA ICS Advisory ICSA-24-165-19 published 2024-06-13 confirms clear-text credential storage on physical disk. Vendor remediation includes full disk encryption (LUKS) and column-level database encryption for sensitive data. Devices shipped after 2024-05-10 include encryption by default.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-38280 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-38280

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-38280 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-38280

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-19.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.