Medium severity6.5NVD Advisory· Published Jan 15, 2020· Updated Jun 17, 2026
CVE-2019-9493
CVE-2019-9493
Description
The MyCar Controls of AutoMobility Distribution Inc., mobile application contains hard-coded admin credentials. A remote unauthenticated attacker may be able to send commands to and retrieve data from a target MyCar unit. This may allow the attacker to learn the location of a target, or gain unauthorized physical access to a vehicle. This issue affects AutoMobility MyCar versions prior to 3.4.24 on iOS and versions prior to 4.1.2 on Android. This issue has additionally been fixed in Carlink, Link, Visions MyCar, and MyCar Kia.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:mycarcontrols:mycar_controls:*:*:*:*:*:android:*:*+ 1 more
- cpe:2.3:a:mycarcontrols:mycar_controls:*:*:*:*:*:android:*:*range: <4.1.2
- cpe:2.3:a:mycarcontrols:mycar_controls:*:*:*:*:*:iphone_os:*:*range: <3.4.24
- Range: <3.4.24 (iOS), <4.1.2 (Android)
- Range: <3.4.24 (iOS), <4.1.2 (Android)
- AutoMobility Distribution Inc./MyCar Controlsv5Range: unspecified
Patches
Vulnerability mechanics
References
5- www.kb.cert.org/vuls/id/174715/nvdThird Party AdvisoryUS Government Resource
- www.securityfocus.com/bid/107827nvdThird Party AdvisoryVDB Entry
- itunes.apple.com/us/app/mycar-controls/id1126511815nvdProduct
- mycarcontrols.comnvdProduct
- play.google.com/store/apps/detailsnvdProduct
News mentions
0No linked articles in our index yet.