CVE-2018-11477
Severity CVSS v4.0:
Pending analysis
Type:
CWE-319
Cleartext Transmission of Sensitive Information
Publication date:
30/05/2018
Last modified:
03/10/2019
Description
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or Android application and the OBD dongle are not encrypted. The combination of this vulnerability with the lack of wireless network protection exposes all transferred car data to the public.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:vgate:icar_2_wi-fi_obd2_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:vgate:icar_2_wi-fi_obd2:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



