Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-6541

Опубликовано: 06 июл. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 5.8
EPSS Низкий

Описание

TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor to address the vulnerabilities in CVE-2016-6538, CVE-2016-6539, CVE-2016-6540 and CVE-2016-6541.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:thetrackr:trackr_bravo_firmware:*:*:*:*:*:android:*:*
Версия до 2.2.5 (исключая)
cpe:2.3:o:thetrackr:trackr_bravo_firmware:*:*:*:*:*:iphone_os:*:*
Версия до 5.1.6 (исключая)
cpe:2.3:h:thetrackr:trackr_bravo:-:*:*:*:*:*:*:*

EPSS

Процентиль: 70%
0.00632
Низкий

8.8 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-306
CWE-287

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

TrackR Bravo device allows unauthenticated pairing, which enables unauthenticated connected applications to write to various device attributes. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor to address the vulnerabilities in CVE-2016-6538, CVE-2016-6539, CVE-2016-6540 and CVE-2016-6541.

EPSS

Процентиль: 70%
0.00632
Низкий

8.8 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-306
CWE-287