ID

VAR-201707-1361


TITLE

Bako Travel Android App Has Any User Password Reset Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2017-09708

DESCRIPTION

Bago Travel is a car time-sharing and sharing platform created by Beijing Bago Car Leasing Co., Ltd. With the help of the Internet of Things technology and advanced operation model, it realizes an unattended, rent-and-pay smart car usage method, and is committed to providing users with Provide 24-hour safe, convenient and economical car service, improve urban travel efficiency, reduce congestion and emissions, and build a beautiful travel experience. There is an arbitrary user password reset vulnerability in the Android app of Ba Ge Travel. An attacker can use this vulnerability to reset their password arbitrarily.

Trust: 0.6

sources: CNVD: CNVD-2017-09708

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-09708

AFFECTED PRODUCTS

vendor:bago car rentalmodel:travel appscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2017-09708

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-09708
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2017-09708
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-09708

PATCH

title:Bako Travel Android App Has Any User Password Reset Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/95604

Trust: 0.6

sources: CNVD: CNVD-2017-09708

EXTERNAL IDS

db:CNVDid:CNVD-2017-09708

Trust: 0.6

sources: CNVD: CNVD-2017-09708

SOURCES

db:CNVDid:CNVD-2017-09708

LAST UPDATE DATE

2022-05-04T09:51:28.277000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-09708date:2017-06-19T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-09708date:2017-07-11T00:00:00