The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on endpoint and parameter device IDs, which accept arbitrary device IDs without further verification.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2022-07-20T15:24:09.830475Z

Updated: 2024-09-16T22:40:23.174Z

Reserved: 2022-06-24T00:00:00

Link: CVE-2022-34150

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-07-20T16:15:09.227

Modified: 2022-07-27T21:33:56.617

Link: CVE-2022-34150

cve-icon Redhat

No data.