CVE-2012-2567
Status: ModifiedLow (2.6)—
The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP session.
CVSS
- Version: 2.0
- Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N
- Base score: 2.6
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.40%
- Percentile among all scored CVEs: 71
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-255
References
- http://blog.mobiledefense.com/2012/05/mobile-defense-finds-two-security-vulnerabilities-in-xelex-mobiletrack/
- http://secunia.com/advisories/49268
- http://www.kb.cert.org/vuls/id/464683
- http://www.securityfocus.com/bid/53634
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75783
- http://blog.mobiledefense.com/2012/05/mobile-defense-finds-two-security-vulnerabilities-in-xelex-mobiletrack/
- http://secunia.com/advisories/49268
- http://www.kb.cert.org/vuls/id/464683
- http://www.securityfocus.com/bid/53634
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75783
Raw JSON (NVD)
Show
{
"id": "CVE-2012-2567",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-05-22T15:55:02.460",
"references": [
{
"url": "http://blog.mobiledefense.com/2012/05/mobile-defense-finds-two-security-vulnerabilities-in-xelex-mobiletrack/",
"source": "cret@cert.org"
},
{
"url": "http://secunia.com/advisories/49268",
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/464683",
"tags": [
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.securityfocus.com/bid/53634",
"source": "cret@cert.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75783",
"source": "cret@cert.org"
},
{
"url": "http://blog.mobiledefense.com/2012/05/mobile-defense-finds-two-security-vulnerabilities-in-xelex-mobiletrack/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/49268",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/464683",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/53634",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75783",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-255"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP session."
},
{
"lang": "es",
"value": "La aplicación MobileTrack Xelex v2.3.7 y versiones anteriores para Android utiliza credenciales definidas en el código fuente (hardcoded), lo que permite a atacantes remotos obtener información sensible a través de una sesión (1) FTP no cifrada o (2) HTTP no cifrada."
}
],
"lastModified": "2026-06-16T23:41:41.697",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:xelex:mobiletrack:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2308D38B-2DC1-4CB9-A76A-1076286A46C1",
"versionEndIncluding": "2.3.7"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:google:android:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8255F035-04C8-4158-B301-82101711939C"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cret@cert.org"
}