The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on endpoint and parameter device IDs, which accept arbitrary device IDs without further verification.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-200-01 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-07-20 09:15
Updated : 2022-07-27 14:33
NVD link : CVE-2022-34150
Mitre link : CVE-2022-34150
JSON object : View
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
Products Affected
micodus
- mv720_firmware
- mv720