« Volver al listado

CVE-2017-17097

Estado: ModificadaCrítica (9.8)—

gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-17097",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-01-02T15:29:00.293",
  "references": [
    {
      "url": "https://gist.github.com/pak0s/ea7a80c2614d9cd43cfb8230c65c9fec",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://s1.gps-server.net/changelog.txt",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/43431/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://gist.github.com/pak0s/ea7a80c2614d9cd43cfb8230c65c9fec",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://s1.gps-server.net/changelog.txt",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/43431/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-640"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php."
    },
    {
      "lang": "es",
      "value": "gps-server.net GPS Tracking Software (autoalojada) 2.x tiene un procedimiento de restablecimiento de contraseña que restablece inmediatamente contraseñas en una petición no autenticada y, a continuación, envía un email con una contraseña predecible (basada en datos) al administrador. Esto facilita que atacantes remotos obtengan acceso prediciendo esta nueva contraseña. Esto está relacionado con el uso de gmdate para crear contraseñas en fn_connect.php."
    }
  ],
  "lastModified": "2026-06-17T01:10:20.527",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37D32FDC-4E0E-4D4F-A925-723354B67346"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8ED2A968-FFA4-4A48-A343-BAD5138CC05B"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4DC108F-06B8-4842-AA5A-E76215148765"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F49F1BFE-6610-488B-A5CA-9B6B3E27A573"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4DEEEE7-1E25-4577-858C-015F577C9E61"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5DEA6F6F-D6AB-421C-88EF-73571EBA0C9E"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5FF5F24-AD52-4903-AC85-6318CF9D5DE0"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC5F366D-3535-4AFB-AC1C-74490AAC928C"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.1.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1C30E1D-5774-4494-9333-51F6E535BF84"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C65D5A45-E48F-4327-98AF-594D9934D8EC"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "891AE0EC-AECF-4F80-A1B2-683E9FFA84D4"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0AAC1506-95C3-4807-881C-4B14BFD89267"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AA06369-2BAA-4206-B195-B7D6D792EC22"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.2.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0B4DBB6-112B-4125-8431-EDC3A38FED97"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68EE9173-962C-4185-8520-F9F2326D4001"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14AB766B-0856-4E34-B8F0-AEC9372C423D"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6864D09-771A-48D8-A30E-957E34187261"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC66FF2E-6A17-42A8-A94D-C2CA60614E1C"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.4.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F395A15-8CB8-4B7B-A351-64B82339F356"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AC5E32A-CFA0-4800-ABE4-5752A7880D0E"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.5.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F65ABBF2-F58E-47AC-B396-53C5CFF28350"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.5.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D222D4CF-2AB8-41E9-A6B6-4C923D365E7B"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.5.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E39F7509-D72D-4479-A0AB-F5E9E9D2A18F"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.5.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "189AFBF0-67D6-4F81-B845-98235C089646"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B285616-5530-449D-BC51-F994BA3F4525"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29A52204-3842-488D-985D-55677B3BDAFB"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85F8F310-3649-496F-B310-FEBFEE764927"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.8.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3221F37-C787-4DDB-9358-CB3A01D88567"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4321076A-15CD-4D5C-8499-028DD7E78760"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E32A8C0-314D-4698-B7B2-FF3A205B67B3"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FD4C15D-E786-4B08-888B-B10886512807"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.9.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "784E2B80-6473-4380-B669-BD7BE217B5B0"
            },
            {
              "criteria": "cpe:2.3:a:gps-server:gps_tracking_software:2.9.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40709D43-841E-40D8-9A0F-E32584099E4B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}