An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to subvert security mechanisms and reset a user account password.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/102481 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-17-234-04 | Mitigation Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/102481 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-17-234-04 | Mitigation Third Party Advisory US Government Resource |
Configurations
History
21 Nov 2024, 03:10
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/102481 - Third Party Advisory, VDB Entry | |
References | () https://ics-cert.us-cert.gov/advisories/ICSA-17-234-04 - Mitigation, Third Party Advisory, US Government Resource |
Information
Published : 2018-01-09 21:29
Updated : 2024-11-21 03:10
NVD link : CVE-2017-12695
Mitre link : CVE-2017-12695
CVE.ORG link : CVE-2017-12695
JSON object : View
Products Affected
gm
- shanghai_onstar
CWE
CWE-287
Improper Authentication