PT-2018-7258 · Calamp · Calamp Lmu 3030 Series
Published
2018-07-24
·
Updated
2019-10-09
·
CVE-2017-3217
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
CalAmp LMU 3030 series OBD-II CDMA and GSM devices (affected versions not specified)
Description:
The issue concerns an SMS interface in the devices that can be exploited if no password is configured. An attacker can send administrative commands to the device by knowing its phone number, potentially gained through an IMSI Catcher. These commands allow for real-time access and configuration of parameters like IP addresses, firewall rules, and passwords.
Recommendations:
For CalAmp LMU 3030 series OBD-II CDMA and GSM devices, configure a password for the SMS interface to prevent unauthorized access. As a temporary workaround, consider restricting access to the SMS interface until a secure configuration can be implemented.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Calamp Lmu 3030 Series