The access controls on the Mobility read-only API improperly validate user admittance permissions. Attackers with both network admittance to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14. (CVSS:0.0) (Terminal Update:2021-09-16)

