Vulnerabilities

Critical security flaws found in top carmakers

0

BMW, Mercedes, Toyota, and other popular carmakers contained API security vulnerabilities that could have allowed attackers to perform malicious activities ranging from unlocking, starting, and tracking cars to exposing customers’ personal information.

Cybersecurity researcher Sam Curry and his colleagues discovered many vulnerabilities in the vehicles manufactured by tens of carmakers and services implemented by vehicle solutions providers.

These vulnerabilities could have been exploited by threat actors to perform a wide range of malicious activities, from unlocking cars to tracking them.

The flaws discovered by the experts affected vehicles of popular brands, including Kia, Honda, Infiniti, Nissan, Acura, Mercedes-Benz, Genesis, BMW, Rolls Royce, Ferrari, Ford, Porsche, Toyota, Jaguar, Land Rover. The research team also discovered flaws in the services provided by Reviver, SiriusXM, and Spireon.

On exploitation of some flaws, the experts were able to access hundreds of Mercedes mission-critical internal applications via improperly configured SSO. An attacker could have also exploited them to achieve remote code execution on multiple systems. The flaws also allowed attackers to access to the content of the memory of some systems, leading to the exposure of Mercedes’ employee/customer PII.

In the case of BMW and Rolls Royce, SSO vulnerabilities were found by experts which allowed them to access any employee application as any employee. The experts were able to access to internal dealer portals and retrieve sales documents for BMW by providing VIN numbers.

The experts were also able to access any application locked behind SSO on behalf of any employee, including applications used by remote workers and dealerships.

Experts managed to achieve a full vehicle takeover on Kia via deprecated dealer portal.

Some of the vulnerabilities discovered by the experts allowed the researchers to retrieve owner information, including the address, in other cases the flaws allowed tracking vehicles.

The experts also demonstrated how to exploit some flaws to access the Reviver license plate service and update any vehicle status to “STOLEN” which updates the license plate and informs the authorities.

However, all the flaws discovered by the experts were addressed by the carmakers and service providers.

Image Credits : Toyotasystems

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Rail giant Wabtec discloses data breach after Lockbit ransomware attack

Previous article

Data of 235 million Twitter users exposed by hackers

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *