CVE-2020-17483: High severity uffizio gps tracker vulnerability
An improper access control vulnerability exists in Uffizio's GPS Tracker all versions that lead to sensitive information disclosure of all the connected devices. By visiting the vulnerable host at port 9000, we see it responds with a JSON body that has all the details about the devices which have been deployed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-17483?
CVE-2020-17483 is classified as a high-severity vulnerability due to improper access controls leading to sensitive information disclosure.
How do I fix CVE-2020-17483?
To fix CVE-2020-17483, ensure that access controls are implemented properly to restrict access to sensitive information on Uffizio's GPS Tracker.
What devices are affected by CVE-2020-17483?
CVE-2020-17483 affects all versions of Uffizio's GPS Tracker software.
What type of data is exposed due to CVE-2020-17483?
CVE-2020-17483 exposes sensitive information regarding all connected devices to unauthorized users.
How can I determine if my system is vulnerable to CVE-2020-17483?
To determine vulnerability to CVE-2020-17483, check if your system is running any version of Uffizio's GPS Tracker and test access controls for sensitive data.