The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on endpoint and POST parameter “Device ID,” which accepts arbitrary device IDs.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-200-01 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2022-07-20T15:24:26.564063Z
Updated: 2024-09-17T02:42:35.600Z
Reserved: 2022-06-24T00:00:00
Link: CVE-2022-33944
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-07-20T16:15:09.160
Modified: 2024-11-21T07:08:39.380
Link: CVE-2022-33944
Redhat
No data.