CVE-2017-3217
Last modified
CVE-2017-3217 is a vulnerability of currently unknown severity. CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SMS (text message) interface that can be deployed where no password is configured for this interface by the integrator / reseller. This interface must be password protected, otherwise, the attacker only needs to know the phone number of the device (via an IMSI Catcher, for example) to send administrative commands to the device. EPSS estimates a 2.05% chance of exploitation in the next 30 days.
Description
CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SMS (text message) interface that can be deployed where no password is configured for this interface by the integrator / reseller. This interface must be password protected, otherwise, the attacker only needs to know the phone number of the device (via an IMSI Catcher, for example) to send administrative commands to the device. These commands can be used to provide ongoing, real-time access to the device and can configure parameters such as IP addresses, firewall rules, and passwords.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Calamp | Lmu 3030 Obd-Ii Firmware | All versions |
| Calamp | Lmu 3030 Cdma Firmware | All versions |
| Calamp | Lmu 3030 Gsm Firmware | All versions |
References
- https://www.kb.cert.org/vuls/id/251927Third Party Advisory, US Government Resource
- https://www.securityfocus.com/bid/98964Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/251927Third Party Advisory, US Government Resource
- https://www.securityfocus.com/bid/98964Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-3217?
How severe is CVE-2017-3217?
How do I fix CVE-2017-3217?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-3211Yopify, an e-commerce notification plugin, up to April 06, 2…5.3
- CVE-2017-3212The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.…5.9
- CVE-2017-3213The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does …
- CVE-2017-3214The Milwaukee ONE-KEY Android mobile application stores the …7.5
- CVE-2017-3215The Milwaukee ONE-KEY Android mobile application uses bearer…
- CVE-2017-3216WiMAX routers based on the MediaTek SDK (libmtk) that use a …
- CVE-2017-3218Samsung Magician 5.0 fails to validate TLS certificates for …
- CVE-2017-3219Acronis True Image up to and including version 2017 Build 80…
- CVE-2017-3221Blind SQL injection in Inmarsat AmosConnect 8 login form all…
- CVE-2017-3222Hard-coded credentials in AmosConnect 8 allow remote attacke…9.8
- CVE-2017-3223Dahua IP camera products using firmware versions prior to V2…
- CVE-2017-3224Open Shortest Path First (OSPF) protocol implementations may…
Are you affected by CVE-2017-3217?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
