CVE-2017-9663

HIGH

GM Shanghai OnStar iOS Client 7.1 - Cleartext Storage of Sensitive Information

Title source: llm
STIX 2.1

Description

An Cleartext Storage of Sensitive Information issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow a remote attacker to access an encryption key that is stored in cleartext in memory.

References (2)

Core 2
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-234-04
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102481

Scores

CVSS v3 7.5
EPSS 0.0107
EPSS Percentile 60.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-312
Status published
Products (1)
gm/shanghai_onstar 7.1
Published Jan 09, 2018
Tracked Since Feb 18, 2026