Bransys ELD
Summary
Multiple vulnerabilities have been identified in Bransys ELD versions prior to Android <11.00.00 and iOS <1.1.54. Successful exploitation could allow unauthorized access to telemetry data and firmware through hard-coded credentials and cleartext transmission of sensitive information.
IFF Assessment
The identified vulnerabilities allow unauthorized access to sensitive data and firmware, posing a significant risk to defenders.
Severity
The CVSS score of 7.5 (HIGH) is based on a network attack vector, low complexity, no privileges required, no user interaction, and a high impact on confidentiality, indicating a critical vulnerability.
Defender Context
Defenders should be aware of these vulnerabilities affecting Bransys ELD, particularly in the transportation sector. The use of hard-coded credentials and cleartext transmission highlights a need for secure coding practices and regular vulnerability scanning.