Impact
The SirenGPS Android Application version 2.19.44 is vulnerable to an Incorrect Access Control flaw. An authenticated attacker can manipulate user identifier parameters in API requests to bypass authorization checks, gaining unintended read and write privileges on other users' personal data. This weakness allows the attacker to compromise data confidentiality and integrity, potentially leading to privacy violations and unauthorized data modification.
Affected Systems
The vulnerability affects the SirenGPS Android Application, specifically version 2.19.44. Users running this version on Android devices are exposed to the risk. No other versions or products are currently listed as impacted.
Risk and Exploitability
The nature of the flaw indicates a high severity because an attacker can directly access and alter personal information of other users. The EPSS score is not available, but the issue can be exploited by any authenticated account simply by manipulating user ID parameters, so the likelihood of exploitation is significant. The flaw is not yet listed in the CISA KEV catalog, yet it may already be actively exploited by malicious actors using the mobile app’s API.
OpenCVE Enrichment