An improper access control vulnerability exists in Uffizio's GPS Tracker all versions that lead to sensitive information disclosure of all the connected devices. By visiting the vulnerable host at port 9000, we see it responds with a JSON body that has all the details about the devices which have been deployed.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-21-287-02 Third Party Advisory US Government Resource
https://www.uffizio.com/ Product
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-16T00:00:00

Updated: 2023-12-16T00:51:18.073765

Reserved: 2020-08-11T00:00:00


Link: CVE-2020-17483

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-16T01:15:07.200

Modified: 2023-12-20T16:39:34.913


Link: CVE-2020-17483

JSON object: View

cve-icon Redhat Information

No data.