Overview
Xelex Technologies' MobileTrack application has been reported to not verify the source of administrative SMS commands. An unauthenticated remote attacker can send commands over SMS to MobileTrack. User data is also exposed on an insecure FTP server account.
Description
The website for MobileTrack states: "MobileTrack is a real-time mobile application platform that empowers organizations and individuals through Mobile Resource Management solutions. Customers can have visibility and control based on where a phone is located and how it is being used in real-time. With permission granted, a simple-to-install phone client is loaded directly onto a mobile smart phone and customers can quickly gain control of their mobile operations." |
Impact
An unauthenticated remote attacker may be able to uninstall the application or wipe the device. If FTP is used, user data on Xelex's FTP server may be exposed. |
Solution
Apply an Update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Temporal | 5.5 | E:U/RL:U/RC:UR |
Environmental | 1.4 | CDP:ND/TD:L/CR:ND/IR:ND/AR:ND |
References
- http://www.xelex.net/mobiletrack/
- http://play.google.com/store/apps/details?id=com.mobiletrack
- http://blog.mobiledefense.com/2012/05/mobile-defense-finds-two-security-vulnerabilities-in-xelex-mobiletrack/
- http://cwe.mitre.org/data/definitions/306.html
- http://cwe.mitre.org/data/definitions/798.html
- http://cwe.mitre.org/data/definitions/200.html
- http://cwe.mitre.org/data/definitions/311.html
Acknowledgements
Thanks to the Mobile Defense Threat Research Team for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2012-2562, CVE-2012-2567 |
Date Public: | 2012-05-21 |
Date First Published: | 2012-05-21 |
Date Last Updated: | 2014-07-29 21:57 UTC |
Document Revision: | 49 |