CVE-2017-17097
Estado: ModificadaCrítica (9.8)—
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 6.95%
- Percentil entre todas las CVEs puntuadas: 94
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-640
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-17097",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": true,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2018-01-02T15:29:00.293",
"references": [
{
"url": "https://gist.github.com/pak0s/ea7a80c2614d9cd43cfb8230c65c9fec",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://s1.gps-server.net/changelog.txt",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/43431/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://gist.github.com/pak0s/ea7a80c2614d9cd43cfb8230c65c9fec",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://s1.gps-server.net/changelog.txt",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/43431/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-640"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php."
},
{
"lang": "es",
"value": "gps-server.net GPS Tracking Software (autoalojada) 2.x tiene un procedimiento de restablecimiento de contraseña que restablece inmediatamente contraseñas en una petición no autenticada y, a continuación, envía un email con una contraseña predecible (basada en datos) al administrador. Esto facilita que atacantes remotos obtengan acceso prediciendo esta nueva contraseña. Esto está relacionado con el uso de gmdate para crear contraseñas en fn_connect.php."
}
],
"lastModified": "2026-06-17T01:10:20.527",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37D32FDC-4E0E-4D4F-A925-723354B67346"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8ED2A968-FFA4-4A48-A343-BAD5138CC05B"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4DC108F-06B8-4842-AA5A-E76215148765"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F49F1BFE-6610-488B-A5CA-9B6B3E27A573"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4DEEEE7-1E25-4577-858C-015F577C9E61"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5DEA6F6F-D6AB-421C-88EF-73571EBA0C9E"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C5FF5F24-AD52-4903-AC85-6318CF9D5DE0"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC5F366D-3535-4AFB-AC1C-74490AAC928C"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E1C30E1D-5774-4494-9333-51F6E535BF84"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C65D5A45-E48F-4327-98AF-594D9934D8EC"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "891AE0EC-AECF-4F80-A1B2-683E9FFA84D4"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0AAC1506-95C3-4807-881C-4B14BFD89267"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.2.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4AA06369-2BAA-4206-B195-B7D6D792EC22"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.2.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0B4DBB6-112B-4125-8431-EDC3A38FED97"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68EE9173-962C-4185-8520-F9F2326D4001"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.3.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "14AB766B-0856-4E34-B8F0-AEC9372C423D"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.3.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B6864D09-771A-48D8-A30E-957E34187261"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC66FF2E-6A17-42A8-A94D-C2CA60614E1C"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.4.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F395A15-8CB8-4B7B-A351-64B82339F356"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4AC5E32A-CFA0-4800-ABE4-5752A7880D0E"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.5.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F65ABBF2-F58E-47AC-B396-53C5CFF28350"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.5.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D222D4CF-2AB8-41E9-A6B6-4C923D365E7B"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.5.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E39F7509-D72D-4479-A0AB-F5E9E9D2A18F"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.5.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "189AFBF0-67D6-4F81-B845-98235C089646"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B285616-5530-449D-BC51-F994BA3F4525"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29A52204-3842-488D-985D-55677B3BDAFB"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "85F8F310-3649-496F-B310-FEBFEE764927"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.8.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D3221F37-C787-4DDB-9358-CB3A01D88567"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4321076A-15CD-4D5C-8499-028DD7E78760"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.9.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E32A8C0-314D-4698-B7B2-FF3A205B67B3"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.9.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7FD4C15D-E786-4B08-888B-B10886512807"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.9.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "784E2B80-6473-4380-B669-BD7BE217B5B0"
},
{
"criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.9.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40709D43-841E-40D8-9A0F-E32584099E4B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}