The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on endpoint and parameter device IDs, which accept arbitrary device IDs without further verification.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2022-07-20T15:24:09.830475Z

Updated: 2024-09-16T22:40:23.174Z

Reserved: 2022-06-24T00:00:00

Link: CVE-2022-34150

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-07-20T16:15:09.227

Modified: 2024-11-21T07:08:57.267

Link: CVE-2022-34150

cve-icon Redhat

No data.