Impact
The SirenGPS Android Application version 2.19.44 is vulnerable to an Incorrect Access Control flaw. An authenticated attacker can manipulate user identifier parameters in API requests to bypass authorization checks, gaining unintended read and write privileges on other users' personal data. This weakness allows the attacker to compromise data confidentiality and integrity, potentially leading to privacy violations and unauthorized data modification.
Affected Systems
The vulnerability affects the SirenGPS Android Application, specifically version 2.19.44. Users running this version on Android devices are exposed to the risk. No other versions or products are currently listed as impacted.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity because an attacker can directly access and alter personal information of other users. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, yet the flaw can still be exploited by any authenticated account simply by manipulating user ID parameters, so the likelihood of exploitation remains significant. The flaw is not yet listed in the CISA KEV catalog, yet it may already be actively exploited by malicious actors using the mobile app’s API.
OpenCVE Enrichment