CVE-2016-6540 Information
Share on:
Feb 14, 2021
cve
Description
Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data for any Trackr device by using the tracker ID number which can be discovered as described in CVE-2016-6539. Updated apps version 5.1.6 for iOS and 2.2.5 for Android have been released by the vendor to address the vulnerabilities in CVE-2016-6538 CVE-2016-6539 CVE-2016-6540 and CVE-2016-6541.
CVSS Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
http://www.securityfocus.com/bid/93874 https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/ https://www.kb.cert.org/vuls/id/617567 https://www.kb.cert.org/vuls/id/TNOY-AF3KCZ
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5