PT-2024-22955 · Cmsv6 · Cmsv6

Published

2024-03-25

·

Updated

2024-08-27

·

CVE-2024-29666

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vehicle Monitoring platform system CMSV6 versions 7.31.0.2 through 7.32.0.3
Description The issue allows a remote attacker to escalate privileges via the default password component. This is an Insecure Permissions vulnerability.
Recommendations For versions 7.31.0.2 through 7.32.0.3, consider changing the default password component to prevent privilege escalation. As a temporary workaround, restrict access to the default password component until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-29666

Affected Products

Cmsv6