4

Vulnerability allows hackers to unlock and start Honda cars remotely | TechSpot

 2 years ago
source link: https://www.techspot.com/news/95239-hackers-discover-vulnerability-allowing-remote-starts-unlocks-popular.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Vulnerability allows hackers to unlock and start Honda cars remotely

The keyless entry vulnerability could potentially impact other non-Honda makes and models

By Jimmy Pezzone July 9, 2022, 9:16 AM 14 comments
Vulnerability allows hackers to unlock and start Honda cars remotely

WTF?! Researchers recently uncovered a vulnerability that could allow hackers to unlock and start multiple Honda vehicle models remotely. The impacted model list identifies 10 of Honda's most popular models as vulnerable. To make matters worse, the current findings lead researchers to believe that the vulnerability could be present on all Honda vehicles from 2012 through 2022.

The security flaw, dubbed RollingPWN by researchers, exploits a component of Honda's keyless entry system. The current entry system relies on a rolling code model that creates a new entry code each time owners press the fob button. Once issued, the previous ones should be made unusable to prevent replay attacks. Instead, researchers Kevin26000 and Wesley Li discovered the old codes could be rolled back and used to obtain unwanted access to the vehicle.

The researchers tested the vulnerability across several Honda models ranging from 2012 through 2022. The list of affected test vehicles includes:

  • Honda Civic 2012
  • Honda XR-V 2018
  • Honda CR-V 2020
  • Honda Accord 2020
  • Honda Odyssey 2020
  • Honda Inspire 2021
  • Honda Fit 2022
  • Honda Civic 2022
  • Honda VE-1 2022
  • Honda Breeze 2022

Based on the list and successful tests of the exploit, Kevin26000 and Li strongly believe the vulnerability could affect all Honda vehicles and not just the initial ten listed above.

2022-07-09-image-8.jpg

Providing a fix for the vulnerability may be as complex as the exploit itself. Honda could patch the flaw via an over-the-air (OTA) firmware update, but many of the cars affected don't provide OTA support. The larger pool of potentially impacted vehicles makes a recall scenario unlikely.

Ladies and gentlemen, it is my honor to presenting you the Rolling-Pwn attack research on Honda Keyfob system. (https://t.co/UqJEJofxtr) pic.twitter.com/3ZccqfJrUa

— Kevin2600 (@Kevin2600) July 7, 2022

For now, research is ongoing to determine how widespread the vulnerability is. Based on the nature of the attack, Kevin26000 and Li strongly suspect that the issue may also impact other car makers.

The finding is just one more in a series of access vulnerabilities discovered across Honda's line of vehicles this year. In March, researchers identified a man-in-the-middle exploit (CVE-2022-27254) where RF signals could be intercepted and manipulated for later use. Kevin26000 had also reported a similar replay attack (CVE-2021-46145) back in January 2022.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK