CVE-2024-3109: Medium severity Motorola GuideMe vulnerability
A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3109?
CVE-2024-3109 has been classified as a medium severity vulnerability due to its potential for local file access by attackers.
How do I fix CVE-2024-3109?
To mitigate CVE-2024-3109, users should update their Motorola GuideMe application to the latest version that addresses the hard-coded AES key and URI sanitation issues.
What type of attacks are possible with CVE-2024-3109?
CVE-2024-3109 could allow local attackers to read arbitrary files on the device due to the hard-coded AES key and insufficient URI sanitation.
Which application is affected by CVE-2024-3109?
CVE-2024-3109 specifically affects the Motorola GuideMe application.
Is remote exploitation possible with CVE-2024-3109?
No, CVE-2024-3109 is a local vulnerability, meaning it requires physical access to the device for exploitation.