Vulnerability Description
The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanism against brute-force attacks on the authentication process, which makes it easier for attackers to obtain multimedia-screen access via port 7050 on the cellular network, as demonstrated by a DrivingRestriction method call to uma/jsonrpc/mobile.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Telenav | Scout Gps Link | >= 1.0.4, <= 1.0.109 |
Related Weaknesses (CWE)
References
- https://sites.google.com/site/iosappnss/more-vulnerable-apps-and-librariesExploitThird Party Advisory
- https://sites.google.com/site/iosappnss/more-vulnerable-apps-and-librariesExploitThird Party Advisory
FAQ
What is CVE-2019-14951?
CVE-2019-14951 is a vulnerability with a CVSS score of 7.5 (HIGH). The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanism against brute-force attacks on the authentication process, which makes it easi...
How severe is CVE-2019-14951?
CVE-2019-14951 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14951?
Check the references section above for vendor advisories and patch information. Affected products include: Telenav Scout Gps Link.