CVE-2016-6542
Summary
| CVE | CVE-2016-6542 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-13 20:29:00 UTC |
| Updated | 2019-10-09 23:19:00 UTC |
| Description | The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an iTrack device. The tracker ID is the device's BLE MAC address. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ieasytec | Itrackeasy | - | All | All | All |
| Application | Ieasytec | Itrackeasy | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability Note VU#974055 - iTrack Easy contains multiple vulnerabilities | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Multiple Bluetooth Low Energy (BLE) Tracker Vulnerabilities | MISC | blog.rapid7.com | Mitigation |
| iTrack Easy VU#974055 Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Thanks to Deral Heiland and Adam Compton of Rapid7, Inc. for reporting this vulnerability.
There are currently no legacy QID mappings associated with this CVE.