The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-200-01 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2022-07-20T15:24:35.820814Z
Updated: 2024-09-17T01:11:16.735Z
Reserved: 2022-06-16T00:00:00
Link: CVE-2022-2107
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-07-20T16:15:08.903
Modified: 2024-11-21T07:00:19.953
Link: CVE-2022-2107
Redhat
No data.