Vulnerability Management, Data Security

Vulnerabilities in automaker’s online platform risk remote vehicle hacking, data compromise

Threat actors could leverage security issues impacting a major unnamed automaker's online platform used by over 1,000 dealerships across the U.S. to facilitate remote vehicle compromise and personal data exfiltration, according to SecurityWeek.

Aside from enabling the discovery of account registration forms and the creation of a 'national admin account' allowing total platform access, the automaker's platform also has vulnerabilities permitting vehicle ownership transfers to a new account, reported Harness researcher Eaton Zveare at the DEF CON 33 security conference. All car models since 2012 with a standard telematics module could also be remotely located, unlocked, or started by threat actors with a knowledge of their owners' names, said Zveare. Moreover, attackers could also harness the flaws to obtain customer and employee information, including personal details, financial documents, contracts, and automobile tracking details, noted the researcher, who added that the bugs were since addressed by the automaker.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds