PT-2018-7258 · Calamp · Calamp Lmu 3030 Series

Published

2018-07-24

·

Updated

2019-10-09

·

CVE-2017-3217

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: CalAmp LMU 3030 series OBD-II CDMA and GSM devices (affected versions not specified)
Description: The issue concerns an SMS interface in the devices that can be exploited if no password is configured. An attacker can send administrative commands to the device by knowing its phone number, potentially gained through an IMSI Catcher. These commands allow for real-time access and configuration of parameters like IP addresses, firewall rules, and passwords.
Recommendations: For CalAmp LMU 3030 series OBD-II CDMA and GSM devices, configure a password for the SMS interface to prevent unauthorized access. As a temporary workaround, consider restricting access to the SMS interface until a secure configuration can be implemented.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-3217

Affected Products

Calamp Lmu 3030 Series