CVE-2016-6540
Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data for any Trackr device by using the tracker ID number which can be discovered as described in CVE-2016-6539.
Does this matter?
Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.
Description
Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data for any Trackr device by using the tracker ID number which can be discovered as described in CVE-2016-6539. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor to address the vulnerabilities in CVE-2016-6538, CVE-2016-6539, CVE-2016-6540 and CVE-2016-6541.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306, CWE-200
- Affected
- thetrackr/trackr bravo firmware
- Source
- cret@cert.org
References
- http://www.securityfocus.com/bid/93874Third Party Advisory, VDB Entry
- https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/Third Party Advisory
- https://www.kb.cert.org/vuls/id/617567Third Party Advisory, US Government Resource
- https://www.kb.cert.org/vuls/id/TNOY-AF3KCZThird Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/93874Third Party Advisory, VDB Entry
- https://blog.rapid7.com/2016/10/25/multiple-bluetooth-low-energy-ble-tracker-vulnerabilities/Third Party Advisory
- https://www.kb.cert.org/vuls/id/617567Third Party Advisory, US Government Resource
- https://www.kb.cert.org/vuls/id/TNOY-AF3KCZThird Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.