{"api_version":"1","generated_at":"2026-07-23T20:57:13+00:00","cve":"CVE-2016-6542","urls":{"html":"https://cve.report/CVE-2016-6542","api":"https://cve.report/api/cve/CVE-2016-6542.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-6542","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-6542"},"summary":{"title":"CVE-2016-6542","description":"The iTrack device tracking ID number, also called \"LosserID\" in the web API, can be obtained by being in the range of an iTrack device. The tracker ID is the device's BLE MAC address.","state":"PUBLIC","assigner":"cert@cert.org","published_at":"2018-07-13 20:29:00","updated_at":"2019-10-09 23:19:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://www.kb.cert.org/vuls/id/974055","name":"VU#974055","refsource":"CERT-VN","tags":["Third Party Advisory","US Government Resource"],"title":"Vulnerability Note VU#974055 - iTrack Easy contains multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/","name":"https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/","refsource":"MISC","tags":["Mitigation"],"title":"Multiple Bluetooth Low Energy (BLE) Tracker Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/93875","name":"93875","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"iTrack Easy VU#974055 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-6542","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-6542","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Thanks to Deral Heiland and Adam Compton of Rapid7, Inc. for reporting this vulnerability.","lang":""}],"nvd_cpes":[{"cve_year":"2016","cve_id":"6542","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ieasytec","cpe5":"itrackeasy","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"6542","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ieasytec","cpe5":"itrackeasy","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2016-6542","STATE":"PUBLIC","TITLE":"The MAC address/device tracking ID of an iTrack Easy can be obtained within range of the device"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Easy","version":{"version_data":[{"affected":"?","version_value":"N/A"}]}}]},"vendor_name":"iTrack"}]}},"credit":[{"lang":"eng","value":"Thanks to Deral Heiland and Adam Compton of Rapid7, Inc. for reporting this vulnerability."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The iTrack device tracking ID number, also called \"LosserID\" in the web API, can be obtained by being in the range of an iTrack device. The tracker ID is the device's BLE MAC address."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-200: Information Exposure"}]}]},"references":{"reference_data":[{"name":"VU#974055","refsource":"CERT-VN","url":"https://www.kb.cert.org/vuls/id/974055"},{"name":"https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/","refsource":"MISC","url":"https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/"},{"name":"93875","refsource":"BID","url":"http://www.securityfocus.com/bid/93875"}]},"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2018-07-13 20:29:00","lastModifiedDate":"2019-10-09 23:19:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"},"exploitabilityScore":2.2,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ieasytec:itrackeasy:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"6542","Ordinal":"92844","Title":"CVE-2016-6542","CVE":"CVE-2016-6542","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"6542","Ordinal":"1","NoteData":"The iTrack device tracking ID number, also called \"LosserID\" in the web API, can be obtained by being in the range of an iTrack device. The tracker ID is the device's BLE MAC address.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"6542","Ordinal":"2","NoteData":"2018-07-13","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"6542","Ordinal":"3","NoteData":"2018-07-14","Type":"Other","Title":"Modified"}]}}}