7.6
CVSSv2

CVE-2012-2562

Published: 22/05/2012 Updated: 29/08/2017
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 676
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Xelex MobileTrack application 2.3.7 and previous versions for Android does not verify the origin of SMS commands, which allows remote malicious users to execute a (1) LOCATE, (2) TRACK, (3) UPDATECFG, (4) UPDATEACCT, (5) STAT, (6) TERM, or (7) WIPE command via an SMS message.

Vulnerable Product Search on Vulmon Subscribe to Product

xelex mobiletrack