A Man-in-the-Middle issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to intercept sensitive information when the client connects to the server.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-17-234-04 | Mitigation Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/102481 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-01-09 13:29
Updated : 2019-10-09 16:23
NVD link : CVE-2017-12697
Mitre link : CVE-2017-12697
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
gm
- shanghai_onstar