Hard-Coded AES Key Vulnerability in Motorola GuideMe Application
CVE-2024-3109
6.3MEDIUM
Summary
A vulnerability has been identified in the Motorola GuideMe application due to the presence of a hard-coded AES key. This flaw, coupled with insufficient URI sanitation, enables a local attacker to exploit the application. If successfully executed, the attacker can gain unauthorized access to read arbitrary files, potentially compromising sensitive information stored on the device.
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published