The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on endpoint and parameter device IDs, which accept arbitrary device IDs without further verification.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-200-01 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2022-07-20 16:15
Updated : 2022-07-27 21:33
NVD link : CVE-2022-34150
Mitre link : CVE-2022-34150
CVE.ORG link : CVE-2022-34150
JSON object : View
Products Affected
micodus
- mv720
- mv720_firmware
CWE
CWE-639
Authorization Bypass Through User-Controlled Key