PT-2018-7258 · Calamp · Calamp Lmu 3030 Series

Publicado

2018-07-24

·

Atualizado

2019-10-09

·

CVE-2017-3217

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: CalAmp LMU 3030 series OBD-II CDMA and GSM devices (affected versions not specified)
Description: The issue concerns an SMS interface in the devices that can be exploited if no password is configured. An attacker can send administrative commands to the device by knowing its phone number, potentially gained through an IMSI Catcher. These commands allow for real-time access and configuration of parameters like IP addresses, firewall rules, and passwords.
Recommendations: For CalAmp LMU 3030 series OBD-II CDMA and GSM devices, configure a password for the SMS interface to prevent unauthorized access. As a temporary workaround, consider restricting access to the SMS interface until a secure configuration can be implemented.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-3217

Produtos afetados

Calamp Lmu 3030 Series