[Forgot Password]
Login  Register Subscribe

23631

 
 

125495

 
 

98503

 
 

909

 
 

79321

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2012-2562

Date: (C)2012-05-22   (M)2017-08-29 


The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows remote attackers to execute a (1) LOCATE, (2) TRACK, (3) UPDATECFG, (4) UPDATEACCT, (5) STAT, (6) TERM, or (7) WIPE command via an SMS message.

CVSS Score: 7.6Access Vector: NETWORK
Exploit Score: 4.9Access Complexity: HIGH
Impact Score: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE





Reference:
SECUNIA-49268
BID-53634
VU#464683
http://blog.mobiledefense.com/2012/05/mobile-defense-finds-two-security-vulnerabilities-in-xelex-mobiletrack/
mobiletrack-sms-commands-sec-bypass(75782)

CPE    1
cpe:/a:xelex:mobiletrack:2.3.7
CWE    1
CWE-20

© 2013 SecPod Technologies