Vendor CVEs
Motorola
All CVEs
145 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2014-9784 | Hig | 0.51 | 7.8 | 0.01 | Jul 11, 2016 | Multiple buffer overflows in drivers/char/diag/diag_debugfs.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28442449 and Qualcomm internal bug… | ||
| CVE-2022-30276 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2022 | The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links)… | ||
| CVE-2022-30275 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2022 | The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini… | ||
| CVE-2020-21934 | Hig | 0.49 | 7.5 | 0.02 | Jul 21, 2021 | An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed. | ||
| CVE-2020-21933 | Hig | 0.49 | 7.5 | 0.01 | Jul 21, 2021 | An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package. | ||
| CVE-2020-10875 | Hig | 0.49 | 7.5 | 0.02 | Mar 23, 2020 | Motorola FX9500 devices allow remote attackers to conduct absolute path traversal attacks, as demonstrated by PL/SQL Server Pages files such as /include/viewtagdb.psp. | ||
| CVE-2020-10874 | Hig | 0.49 | 7.5 | 0.01 | Mar 23, 2020 | Motorola FX9500 devices allow remote attackers to read database files. | ||
| CVE-2019-15513 | Hig | 0.49 | 7.5 | 0.02 | Aug 23, 2019 | An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a long SetWanSettings command, leading to a… | ||
| CVE-2019-13129 | Hig | 0.49 | 7.5 | 0.01 | Jul 1, 2019 | On the Motorola router CX2L MWR04L 1.01, there is a stack consumption (infinite recursion) issue in scopd via TCP port 8010 and UDP port 8080. It is caused by snprintf and inappropriate length handling. | ||
| CVE-2015-7936 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2015 | Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijack the authentication of administrators for requests that modify a password. | ||
| CVE-2015-7935 | Hig | 0.49 | 7.5 | 0.02 | Dec 23, 2015 | Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors. | ||
| CVE-2018-12499 | Hig | 0.48 | 7.4 | 0.00 | Jul 2, 2018 | The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and the servers it communicates with. In one such instance, it was identified that the device was… | ||
| CVE-2022-4002 | Hig | 0.47 | 7.2 | 0.01 | Jul 31, 2024 | A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request. | ||
| CVE-2022-4001 | Hig | 0.47 | 7.3 | 0.00 | Jul 31, 2024 | An authentication bypass vulnerability could allow an attacker to access API functions without authentication. | ||
| CVE-2023-23773 | Hig | 0.47 | 7.2 | 0.00 | Aug 29, 2023 | Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave… | ||
| CVE-2023-23772 | Hig | 0.47 | 7.2 | 0.00 | Aug 29, 2023 | Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material,… | ||
| CVE-2022-34885 | Hig | 0.47 | 7.2 | 0.00 | Jan 30, 2023 | An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permissions to execute arbitrary code. | ||
| CVE-2022-30272 | Hig | 0.47 | 7.2 | 0.00 | Jul 26, 2022 | The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ACE1000 Easy Configurator for performing firmware updates. In case of the Easy Configurator, firmware updates are performed through access to the Web UI where… | ||
| CVE-2025-1700 | Hig | 0.46 | 7.0 | 0.00 | Jul 17, 2025 | A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to escalate privileges during installation of the software. | ||
| CVE-2023-38291 | Hig | 0.46 | 7.1 | 0.00 | Apr 22, 2024 | An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various software builds for the following TCL devices (30Z and 10L) and Motorola devices (Moto G Pure and Moto G Power) leak the Wi-Fi MAC… | ||
| CVE-2021-3898 | Med | 0.44 | 6.8 | 0.00 | Apr 22, 2022 | Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which could lead to the communication channel being accessible by an attacker. | ||
| CVE-2021-3788 | Med | 0.44 | 6.8 | 0.00 | Nov 12, 2021 | An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device. | ||
| CVE-2021-3459 | Med | 0.44 | 6.8 | 0.00 | Aug 17, 2021 | A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary privileged commands to be executed on the adapter. | ||
| CVE-2017-9497 | Med | 0.44 | 6.8 | 0.00 | Jul 31, 2017 | The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to execute arbitrary commands as root by pulling up the diagnostics menu on the set-top box, and then posting to a Web Inspector route. | ||
| CVE-2023-41830 | Med | 0.42 | 6.5 | 0.00 | May 3, 2024 | An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization. | ||
| CVE-2022-3681 | Med | 0.42 | 6.5 | 0.00 | Oct 27, 2023 | A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network. | ||
| CVE-2021-3793 | Med | 0.42 | 6.5 | 0.01 | Nov 12, 2021 | An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware… | ||
| CVE-2021-3791 | Med | 0.42 | 6.5 | 0.00 | Nov 12, 2021 | An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password. | ||
| CVE-2021-3790 | Med | 0.42 | 6.5 | 0.00 | Nov 12, 2021 | A buffer overflow was reported in the local web server of some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same network to perform a denial-of-service attack against the device. | ||
| CVE-2021-3787 | Med | 0.42 | 6.4 | 0.00 | Nov 12, 2021 | A vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with local access to obtain the MQTT credentials that could result in unauthorized access to backend Hubble services. | ||
| CVE-2024-3109 | Med | 0.41 | 6.3 | 0.00 | May 3, 2024 | A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files. | ||
| CVE-2017-9493 | Med | 0.41 | 6.3 | 0.01 | Jul 31, 2017 | The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to conduct successful forced-pairing attacks (between an RF4CE remote and a set-top box) by repeatedly transmitting the same pairing code. | ||
| CVE-2023-41819 | Med | 0.40 | 6.1 | 0.00 | May 3, 2024 | A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers. | ||
| CVE-2021-3458 | Med | 0.40 | 6.1 | 0.00 | Aug 17, 2021 | The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified. | ||
| CVE-2024-3108 | Med | 0.36 | 5.5 | 0.00 | May 3, 2024 | An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization. | ||
| CVE-2017-9498 | Med | 0.36 | 5.5 | 0.00 | Jul 31, 2017 | The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) and Xfinity XR11-20 Voice Remote devices allows local users to upload arbitrary firmware images to an XR11 by leveraging root access. In other words, there is no protection mechanism involving… | ||
| CVE-2016-6678 | Med | 0.36 | 5.5 | 0.00 | Oct 10, 2016 | The Motorola USBNet driver in Android before 2016-10-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 29914434. | ||
| CVE-2020-21936 | Med | 0.35 | 5.3 | 0.01 | Jul 21, 2021 | An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSettings, GetWebsiteFilterSettings and GetNetworkSettings without authentication. | ||
| CVE-2020-21932 | Med | 0.35 | 5.3 | 0.01 | Jul 21, 2021 | A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a partially authorized token and uid. | ||
| CVE-2019-11321 | Med | 0.35 | 5.3 | 0.01 | Apr 18, 2019 | An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC addresses of connected client devices. | ||
| CVE-2017-9494 | Med | 0.35 | 5.3 | 0.01 | Jul 31, 2017 | The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to enable a Remote Web Inspector that is accessible from the public Internet. | ||
| CVE-2024-25360 | Med | 0.34 | 5.3 | 0.00 | Feb 12, 2024 | A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip. | ||
| CVE-2021-3792 | Med | 0.34 | 5.3 | 0.00 | Nov 12, 2021 | Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker. | ||
| CVE-2023-41826 | Med | 0.33 | 5.1 | 0.00 | May 3, 2024 | A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission. | ||
| CVE-2023-41821 | Med | 0.33 | 5.0 | 0.00 | May 3, 2024 | A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information. | ||
| CVE-2023-41820 | Med | 0.33 | 5.0 | 0.00 | May 3, 2024 | An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio devices. | ||
| CVE-2023-41818 | Med | 0.33 | 5.0 | 0.00 | May 3, 2024 | An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker to read system logs. | ||
| CVE-2023-41816 | Med | 0.33 | 5.0 | 0.00 | May 3, 2024 | An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database. | ||
| CVE-2023-41829 | Med | 0.33 | 5.0 | 0.00 | Mar 4, 2024 | An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization. | ||
| CVE-2023-41827 | Med | 0.33 | 5.1 | 0.00 | Mar 4, 2024 | An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI. |
- risk 0.51cvss 7.8epss 0.01
Multiple buffer overflows in drivers/char/diag/diag_debugfs.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28442449 and Qualcomm internal bug…
- risk 0.49cvss 7.5epss 0.01
The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links)…
- risk 0.49cvss 7.5epss 0.01
The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini…
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package.
- risk 0.49cvss 7.5epss 0.02
Motorola FX9500 devices allow remote attackers to conduct absolute path traversal attacks, as demonstrated by PL/SQL Server Pages files such as /include/viewtagdb.psp.
- risk 0.49cvss 7.5epss 0.01
Motorola FX9500 devices allow remote attackers to read database files.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a long SetWanSettings command, leading to a…
- risk 0.49cvss 7.5epss 0.01
On the Motorola router CX2L MWR04L 1.01, there is a stack consumption (infinite recursion) issue in scopd via TCP port 8010 and UDP port 8080. It is caused by snprintf and inappropriate length handling.
- risk 0.49cvss 7.5epss 0.01
Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijack the authentication of administrators for requests that modify a password.
- risk 0.49cvss 7.5epss 0.02
Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.
- risk 0.48cvss 7.4epss 0.00
The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and the servers it communicates with. In one such instance, it was identified that the device was…
- risk 0.47cvss 7.2epss 0.01
A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.
- risk 0.47cvss 7.3epss 0.00
An authentication bypass vulnerability could allow an attacker to access API functions without authentication.
- risk 0.47cvss 7.2epss 0.00
Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave…
- risk 0.47cvss 7.2epss 0.00
Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material,…
- risk 0.47cvss 7.2epss 0.00
An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permissions to execute arbitrary code.
- risk 0.47cvss 7.2epss 0.00
The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ACE1000 Easy Configurator for performing firmware updates. In case of the Easy Configurator, firmware updates are performed through access to the Web UI where…
- risk 0.46cvss 7.0epss 0.00
A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to escalate privileges during installation of the software.
- risk 0.46cvss 7.1epss 0.00
An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various software builds for the following TCL devices (30Z and 10L) and Motorola devices (Moto G Pure and Moto G Power) leak the Wi-Fi MAC…
- risk 0.44cvss 6.8epss 0.00
Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which could lead to the communication channel being accessible by an attacker.
- risk 0.44cvss 6.8epss 0.00
An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device.
- risk 0.44cvss 6.8epss 0.00
A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary privileged commands to be executed on the adapter.
- risk 0.44cvss 6.8epss 0.00
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to execute arbitrary commands as root by pulling up the diagnostics menu on the set-top box, and then posting to a Web Inspector route.
- risk 0.42cvss 6.5epss 0.00
An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization.
- risk 0.42cvss 6.5epss 0.00
A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network.
- risk 0.42cvss 6.5epss 0.01
An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware…
- risk 0.42cvss 6.5epss 0.00
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password.
- risk 0.42cvss 6.5epss 0.00
A buffer overflow was reported in the local web server of some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same network to perform a denial-of-service attack against the device.
- risk 0.42cvss 6.4epss 0.00
A vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with local access to obtain the MQTT credentials that could result in unauthorized access to backend Hubble services.
- risk 0.41cvss 6.3epss 0.00
A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files.
- risk 0.41cvss 6.3epss 0.01
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to conduct successful forced-pairing attacks (between an RF4CE remote and a set-top box) by repeatedly transmitting the same pairing code.
- risk 0.40cvss 6.1epss 0.00
A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers.
- risk 0.40cvss 6.1epss 0.00
The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified.
- risk 0.36cvss 5.5epss 0.00
An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization.
- risk 0.36cvss 5.5epss 0.00
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) and Xfinity XR11-20 Voice Remote devices allows local users to upload arbitrary firmware images to an XR11 by leveraging root access. In other words, there is no protection mechanism involving…
- risk 0.36cvss 5.5epss 0.00
The Motorola USBNet driver in Android before 2016-10-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 29914434.
- risk 0.35cvss 5.3epss 0.01
An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSettings, GetWebsiteFilterSettings and GetNetworkSettings without authentication.
- risk 0.35cvss 5.3epss 0.01
A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a partially authorized token and uid.
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC addresses of connected client devices.
- risk 0.35cvss 5.3epss 0.01
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to enable a Remote Web Inspector that is accessible from the public Internet.
- risk 0.34cvss 5.3epss 0.00
A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip.
- risk 0.34cvss 5.3epss 0.00
Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker.
- risk 0.33cvss 5.1epss 0.00
A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without permission.
- risk 0.33cvss 5.0epss 0.00
A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information.
- risk 0.33cvss 5.0epss 0.00
An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio devices.
- risk 0.33cvss 5.0epss 0.00
An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker to read system logs.
- risk 0.33cvss 5.0epss 0.00
An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database.
- risk 0.33cvss 5.0epss 0.00
An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.
- risk 0.33cvss 5.1epss 0.00
An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI.
Page 2 of 3