Hard-Coded AES Key Vulnerability in Motorola GuideMe Application
CVE-2024-3109

6.3MEDIUM

Key Information:

Vendor
Motorola
Status
Vendor
CVE Published:
3 May 2024

Summary

A vulnerability has been identified in the Motorola GuideMe application due to the presence of a hard-coded AES key. This flaw, coupled with insufficient URI sanitation, enables a local attacker to exploit the application. If successfully executed, the attacker can gain unauthorized access to read arbitrary files, potentially compromising sensitive information stored on the device.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.