Vulnerability Description
An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device simply produces a "Remove PIN and restart!" message, and cannot be used. This makes it easier for an attacker to use the SIM card by stealing the device.
CVSS Score
MEDIUM
References
- https://seclists.org/fulldisclosure/2024/Jul/14
- https://www.one2track.nl
- http://seclists.org/fulldisclosure/2024/Jul/14
FAQ
What is CVE-2019-20472?
CVE-2019-20472 is a vulnerability with a CVSS score of 6.2 (MEDIUM). An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device simply produces a "Remove PIN and restart!" ...
How severe is CVE-2019-20472?
CVE-2019-20472 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20472?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.