CVE-2017-3217
CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SMS (text message) interface that can be deployed where no password is configured for this interface by the integrator / reseller. This interface must be password protected, otherwise, the attacker only needs to know the phone number of the device (via an IMSI Catcher, for example) to send administrative commands to the device. These commands can be used to provide ongoing, real-time access to the device and can configure parameters such as IP addresses, firewall rules, and passwords.
Published:Jul 24, 2018
Last Modified:Nov 21, 2024
EPS:Jul 24, 2018
EPSS Score:0.00502
CVSS Score:8.1
Affected Products
Vendor
Product
Action
Vendor
Calamp
Product
Lmu 3030 Cdma
Calamp
Lmu 3030 Cdma
Vendor
Calamp
Product
Lmu 3030 Cdma Firmware
Calamp
Lmu 3030 Cdma Firmware
Vendor
Calamp
Product
Lmu 3030 Gsm
Calamp
Lmu 3030 Gsm
Vendor
Calamp
Product
Lmu 3030 Gsm Firmware
Calamp
Lmu 3030 Gsm Firmware
Vendor
Calamp
Product
Lmu 3030 Obd-ii
Calamp
Lmu 3030 Obd-ii
Vendor
Calamp
Product
Lmu 3030 Obd-ii Firmware
Calamp
Lmu 3030 Obd-ii Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
