PatchSiren cyber security CVE debrief
CVE-2024-38280 Motorola Solutions CVE debrief
Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600) stores sensitive data, including credentials, in clear text on the hard disk. An unauthorized user with physical access can retrieve the hard disk and gain access to this sensitive data. The vulnerability affects devices running firmware version 3.1.171.9 and earlier. Motorola Solutions has addressed this by implementing full disk encryption using LUKS standards and GRUB Bootloader password protection on devices shipped after May 10, 2024. For devices unable to receive full disk encryption, all Criminal Justice Information (CJI) data has been encrypted. The CVSS 3.1 score of 6.8 reflects the physical attack vector required, with high impacts to confidentiality, integrity, and availability once access is obtained.
- Vendor
- Motorola Solutions
- Product
- Vigilant Fixed LPR Coms Box (BCAV1F2-C600)
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-06-13
- Original CVE updated
- 2024-06-13
- Advisory published
- 2024-06-13
- Advisory updated
- 2024-06-13
Who should care
Organizations operating Motorola Solutions Vigilant Fixed LPR Coms Box systems, particularly law enforcement and government agencies handling Criminal Justice Information (CJI) subject to CJIS Security Policy requirements. Security teams responsible for physical security of traffic infrastructure and automated license plate recognition deployments.
Technical summary
The Vigilant Fixed LPR Coms Box stores sensitive authentication credentials and Criminal Justice Information (CJI) in unencrypted form on the local hard disk. This allows an attacker with physical access to remove the storage device and extract sensitive data without authentication. The vulnerability is classified as medium severity (CVSS 3.1: 6.8) due to the physical attack vector requirement, though impact is rated high across confidentiality, integrity, and availability dimensions. Remediation requires cryptographic controls: full disk encryption per LUKS standards, bootloader password protection, and column-level database encryption for sensitive fields.
Defensive priority
high
Recommended defensive actions
- Apply full disk encryption using LUKS standards with GRUB Bootloader password protection to all affected devices
- Implement column-level encryption for sensitive database data containing Criminal Justice Information (CJI)
- Verify all devices shipped after May 10, 2024 have encryption enabled; no further action required for these units
- For devices that cannot support full disk encryption, ensure all CJI data is encrypted at the application or database level
- Restrict physical access to LPR Coms Box hardware to authorized personnel only
- Audit existing deployments to identify devices running firmware version 3.1.171.9 or earlier requiring remediation
Evidence notes
CISA ICS Advisory ICSA-24-165-19 published 2024-06-13 confirms clear-text credential storage on physical disk. Vendor remediation includes full disk encryption (LUKS) and column-level database encryption for sensitive data. Devices shipped after 2024-05-10 include encryption by default.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-38280 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-38280
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-38280 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-38280
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-19.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-19
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.