V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2017-17097
CVE
CriticalConfirmedExploit available

gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthentic…

CVSS
9.8
Critical
EPSS
0.37
p97
Published
2017-01-01
Updated
2017-01-01
Description

gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.

Tags · CWE
Pre-auth
CWE-640
CAPEC-50
Affected products
Gps_tracking_software
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.369 · p97
Known exploited (KEV)
No
Known exploits — Сканер-ВС
43431
exploitdb · https://www.exploit-db.com/exploits/43431
Enterprise
Affected software
ProductVendorStatus
gps_tracking_software*Tracked
Source databases
CVE