VulnerabilityModified
CVE-2017-12697
Successful exploitation of this vulnerability may allow an attacker to intercept sensitive information when the client connects to the server.
MEDIUM 5.9EPSS 1.44%
Does this matter?
Lower severity and a low EPSS score (1.44%). Track it; it rarely justifies an emergency change on its own.
Description
A Man-in-the-Middle issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to intercept sensitive information when the client connects to the server.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.44% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-300, CWE-200
- Affected
- gm/shanghai onstar
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/102481Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-234-04Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/102481Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-234-04Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.