Bootloader Vulnerability Allows Attacker to Bypass Authentication and Access File System
CVE-2024-38279

4.6MEDIUM

Key Information:

Vendor
CVE Published:
13 June 2024

Summary

The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.

Affected Version(s)

Vigilant Fixed LPR Coms Box (BCAV1F2-C600) 0 <= 3.1.171.9

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Michigan State Police Michigan Cyber Command Center (MC3)
.