CVE-2025-47824
BaseFortify
Publication date: 2025-06-27
Last updated on: 2025-10-23
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| flocksafety | license_plate_reader_firmware | to 2.2 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-312 | The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves Flock Safety License Plate Reader (LPR) devices with firmware versions up to 2.2 storing code in cleartext. This means that sensitive code or data is not encrypted or protected, potentially allowing unauthorized parties with physical access to the device to read the stored code directly.
How can this vulnerability impact me? :
The impact of this vulnerability is limited due to its low CVSS score (2.0) and the requirement for physical access (Attack Vector: Physical). However, if exploited, it could lead to unauthorized disclosure of code stored on the device, which might aid attackers in understanding or manipulating the device's operation.