Description
Observable response discrepancy vulnerability in HAVELSAN Inc. Geographic Tracking System allows System Footprinting.

This issue affects Geographic Tracking System: before v0.0.2.
Published: 2026-06-05
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An observable response discrepancy in HAVELSAN Inc.'s Geographic Tracking System permits attackers to determine the existence of specific user accounts, effectively enabling system footprinting. The flaw arises because the system returns distinguishable responses when queried with valid versus invalid user identifiers, allowing an adversary to enumerate users without authentication. This user‑enumeration weakness can provide valuable information for targeted lateral movement or credential‑guessing attacks.

Affected Systems

The vulnerability impacts the Geographic Tracking System from HAVELSAN Inc., specifically versions released before 0.0.2. Any deployment lacking an update to 0.0.2 or later remains vulnerable to user‑enumeration attacks.

Risk and Exploitability

The CVSS score of 9.1 classifies this flaw as a critical vulnerability, and although no EPSS score is available, the high severity indicates a substantial threat. Since the flaw can be exploited remotely by sending crafted requests to publicly accessible endpoints, it enables attackers to enumerate users with minimal effort. Although the vulnerability is not listed in CISA's KEV catalog, the potential impact on confidentiality and the ease of exploitation warrant immediate attention.

Generated by OpenCVE AI on June 5, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 0.0.2 or newer to eliminate the response discrepancy.
  • Restrict external access to the Geographic Tracking System APIs using network segmentation or a VPN.
  • Implement rate limiting and response obfuscation to make enumeration more difficult.

Generated by OpenCVE AI on June 5, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 14:45:00 +0000

Type Values Removed Values Added
Description Observable response discrepancy vulnerability in HAVELSAN Inc. Geographic Tracking System allows System Footprinting. This issue affects Geographic Tracking System: before v0.0.2.
Title User Enumeration in in HAVELSAN's Geographic Tracking System
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-06-05T13:49:11.752Z

Reserved: 2026-04-13T12:15:50.181Z

Link: CVE-2026-6207

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-05T15:16:53.730

Modified: 2026-06-05T15:16:53.730

Link: CVE-2026-6207

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T15:30:13Z

Weaknesses