Vgate's vulnerability footprint centers on the iCar 2 Wi-Fi OBD2 vehicle diagnostic device and its firmware, a narrowly scoped connectivity product for automotive diagnostics. The recurring weaknesses—cleartext transmission of sensitive information, improper authentication, and missing authentication for critical functions—reflect the wireless interface and remote-access expectations of an automotive diagnostic tool. Current exposure counts and live severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vgate over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11478HIGH An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and debug information from the car. This on-board diagnostics fe | May 30, 2018 | 8.8 | 25 | NO | NO |
CVE-2018-11476HIGH An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The dongle opens an unprotected wireless LAN that cannot be configured with encryption or a password. This enable | May 30, 2018 | 8.8 | 24 | NO | NO |
CVE-2018-11477MEDIUM An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or Android application and the OBD dongle are not encrypted. The c | May 30, 2018 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vgate.
Media articles that mention a CVE ID that affects a product developed by Vgate — matched by CVE ID, not by vendor name.