A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS data, which can allow unauthenticated parties to track the device.
The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://www.kb.cert.org/vuls/id/974055 | third party advisory us government resource |
https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/ | mitigation third party advisory |
http://www.securityfocus.com/bid/93875 | third party advisory vdb entry |