CVE-2017-12695
Summary
| CVE | CVE-2017-12695 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-09 21:29:00 UTC |
| Updated | 2019-10-09 23:23:00 UTC |
| Description | An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to subvert security mechanisms and reset a user account password. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gm | Shanghai Onstar | 7.1 | All | All | All |
| Application | Gm | Shanghai Onstar | 7.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| General Motors and Shanghai OnStar (SOS) iOS Client | CISA | MISC | ics-cert.us-cert.gov | Mitigation, Third Party Advisory, US Government Resource |
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.