The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on endpoint and parameter device IDs, which accept arbitrary device IDs without further verification.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-200-01 | Third Party Advisory US Government Resource |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: icscert
Published: 2022-07-19T00:00:00
Updated: 2022-07-20T15:24:09
Reserved: 2022-06-24T00:00:00
Link: CVE-2022-34150
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-07-20T16:15:09.227
Modified: 2022-07-27T21:33:56.617
Link: CVE-2022-34150
JSON object: View
Redhat Information
No data.
CWE