ID

VAR-201801-0959


CVE

CVE-2017-12695


TITLE

General Motors - Shanghai OnStar of SOS iOS Client Authentication vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-012083

DESCRIPTION

An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to subvert security mechanisms and reset a user account password. General Motors Shanghai OnStar is prone to multiple security vulnerabilities. An attackers may exploit these issues to gain unauthorized complete access to the affected application by bypassing intended security restrictions or perform man-in-the-middle attack to edit or view sensitive information that may aid in launching further attacks. Shanghai OnStar 7.1 is vulnerable; other versions may also be affected

Trust: 2.61

sources: NVD: CVE-2017-12695 // JVNDB: JVNDB-2017-012083 // CNVD: CNVD-2018-00881 // BID: 102481 // IVD: e2e1a3de-39ab-11e9-aba5-000c29342cb1

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: e2e1a3de-39ab-11e9-aba5-000c29342cb1 // CNVD: CNVD-2018-00881

AFFECTED PRODUCTS

vendor:gmmodel:shanghai onstarscope:eqversion:7.1

Trust: 1.6

vendor:general motors onstarmodel:sos ios clientscope:eqversion:7.1

Trust: 0.8

vendor:generalmodel:motorsgm shanghai onstarsosios clientscope:eqversion:7.1

Trust: 0.6

vendor:generalmodel:motors shanghai onstarscope:eqversion:7.1

Trust: 0.3

vendor:generalmodel:motors shanghai onstarscope:neversion:7.2

Trust: 0.3

vendor:onstarmodel: - scope:eqversion:7.1

Trust: 0.2

sources: IVD: e2e1a3de-39ab-11e9-aba5-000c29342cb1 // CNVD: CNVD-2018-00881 // BID: 102481 // JVNDB: JVNDB-2017-012083 // CNNVD: CNNVD-201801-333 // NVD: CVE-2017-12695

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-12695
value: HIGH

Trust: 1.0

NVD: CVE-2017-12695
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-00881
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201801-333
value: HIGH

Trust: 0.6

IVD: e2e1a3de-39ab-11e9-aba5-000c29342cb1
value: HIGH

Trust: 0.2

nvd@nist.gov: CVE-2017-12695
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-00881
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: e2e1a3de-39ab-11e9-aba5-000c29342cb1
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

nvd@nist.gov: CVE-2017-12695
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: IVD: e2e1a3de-39ab-11e9-aba5-000c29342cb1 // CNVD: CNVD-2018-00881 // JVNDB: JVNDB-2017-012083 // CNNVD: CNNVD-201801-333 // NVD: CVE-2017-12695

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.8

sources: JVNDB: JVNDB-2017-012083 // NVD: CVE-2017-12695

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201801-333

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201801-333

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-012083

PATCH

title:Top Pageurl:https://www.onstar.com/us/en/home/

Trust: 0.8

title:General Motors and Shanghai OnStar iOS Client are not authorized to modify the patch for the vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/113379

Trust: 0.6

sources: CNVD: CNVD-2018-00881 // JVNDB: JVNDB-2017-012083

EXTERNAL IDS

db:NVDid:CVE-2017-12695

Trust: 3.5

db:ICS CERTid:ICSA-17-234-04

Trust: 3.3

db:BIDid:102481

Trust: 2.5

db:CNVDid:CNVD-2018-00881

Trust: 0.8

db:CNNVDid:CNNVD-201801-333

Trust: 0.8

db:JVNDBid:JVNDB-2017-012083

Trust: 0.8

db:IVDid:E2E1A3DE-39AB-11E9-ABA5-000C29342CB1

Trust: 0.2

sources: IVD: e2e1a3de-39ab-11e9-aba5-000c29342cb1 // CNVD: CNVD-2018-00881 // BID: 102481 // JVNDB: JVNDB-2017-012083 // CNNVD: CNNVD-201801-333 // NVD: CVE-2017-12695

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-17-234-04

Trust: 3.0

url:http://www.securityfocus.com/bid/102481

Trust: 2.2

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-12695

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-12695

Trust: 0.8

url:https://www.gm.com/

Trust: 0.3

url:https://ics-cert.us-cert.gov/advisories/icsa-17-234-04 icsa-17-234-04

Trust: 0.3

sources: CNVD: CNVD-2018-00881 // BID: 102481 // JVNDB: JVNDB-2017-012083 // CNNVD: CNNVD-201801-333 // NVD: CVE-2017-12695

CREDITS

Charles Gans

Trust: 0.3

sources: BID: 102481

SOURCES

db:IVDid:e2e1a3de-39ab-11e9-aba5-000c29342cb1
db:CNVDid:CNVD-2018-00881
db:BIDid:102481
db:JVNDBid:JVNDB-2017-012083
db:CNNVDid:CNNVD-201801-333
db:NVDid:CVE-2017-12695

LAST UPDATE DATE

2024-11-23T22:12:41.950000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-00881date:2018-01-15T00:00:00
db:BIDid:102481date:2018-01-09T00:00:00
db:JVNDBid:JVNDB-2017-012083date:2018-02-16T00:00:00
db:CNNVDid:CNNVD-201801-333date:2019-10-17T00:00:00
db:NVDid:CVE-2017-12695date:2024-11-21T03:10:02.843

SOURCES RELEASE DATE

db:IVDid:e2e1a3de-39ab-11e9-aba5-000c29342cb1date:2018-01-15T00:00:00
db:CNVDid:CNVD-2018-00881date:2018-01-15T00:00:00
db:BIDid:102481date:2018-01-09T00:00:00
db:JVNDBid:JVNDB-2017-012083date:2018-02-16T00:00:00
db:CNNVDid:CNNVD-201801-333date:2018-01-10T00:00:00
db:NVDid:CVE-2017-12695date:2018-01-09T21:29:00.267