Описание
Due to a lack of authentication, an unauthenticated user who knows the Eview EV-07S GPS Tracker's phone number can revert the device to a factory default configuration with an SMS command, "RESET!"
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:eviewgps:ev-07s_gps_tracker_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:eviewgps:ev-07s_gps_tracker:-:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02497
Низкий
7.5 High
CVSS3
7.8 High
CVSS2
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Due to a lack of authentication, an unauthenticated user who knows the Eview EV-07S GPS Tracker's phone number can revert the device to a factory default configuration with an SMS command, "RESET!"
EPSS
Процентиль: 85%
0.02497
Низкий
7.5 High
CVSS3
7.8 High
CVSS2
Дефекты
CWE-287