• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / BMW, Ford, Nissan Hacked: use vulnerable modems

BMW, Ford, Nissan Hacked: use vulnerable modems

02/08/2017 21:58 by giorgos

Problems in BMW, Ford, Infiniti and Nissan vehicles. A team of three security researchers discovered two security flaws in the TCU (telematics control unit) components that are contained in various car models connected to the internet.

TCUs are 2G modems which send and receive data from a car's internal system. They are used as an interface between the car and remote management tools, such as web panels and mobile applications.BMW Z4 - BMW, Ford, Nissan Hacked: use vulnerable modems

The researchers found the defects in the TCU manufactured by Continental AG, and more specifically TCUs using the S-Gold 2 (PMB 8876) cellular baseband chipset.

Thus, according to a notice issued by the Department of Homeland Security (DHS), the following car models use vulnerable TCUs:

Affected vehicles

BMW models built between 2009-2010
Ford (a recall program for 2G modems runs from 2016 and so the problem exists in a limited number of vehicles equipped with P-HEV.
Infiniti 2013 JX35
Infiniti 2014-2016 QX60
Infiniti 2014-2016 QX60 Hybrid
Infiniti 2014-2015 QX50
Infiniti 2014-2015 QX50 Hybrid
Infiniti 2013 M37 / M56
Infiniti 2014-2016 Q70
Infiniti 2014-2016 Q70L
Infiniti 2015-2016 Q70 Hybrid
Infiniti 2013 QX56
Infiniti 2014-2016 QX 80
Nissan 2011-2015 Leaf

The two defects relate to a buffer overflow in the TCU element processing the AT commands (CVE-2017-9647) and a flaw that allows attackers to run code via one of the internal elements of the TCU (baseband radio) (CVE-2017-9633).

In the first vulnerability, the attacker would need physical access to the target car, while the latter may take advantage of remote locations. The exploits code (Proof-of-concept or PoC) is available for both defects.

The car makers involved said the defects allow attackers only access to the car's entertainment system and not to critical operations such as braking, engine control or vehicle doors.

BMW said it would "provide service to affected customers" and Nissan said it would turn off 2G modems (TCUs) for all affected customers for free. This measure also applies to owners of Nissan-owned Infiniti cars.

Ford said it started disabling all 2G modem from last year, 2016. The company has told ICS-CERT that there are very few 2G modems on the market.

Security researchers Mickey Shkatov, Jesse Michael and Oleksandr Bazhaniuk from McAfee's Advanced Threat Research Team presented their findings at the DEF CON security conference held in Las Vegas last week. (PDF)

BMW, Ford, Nissan Hacked: use vulnerable modems was last modified: August 2, 2017, 9: 58 mm by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: NewsDay: 2009, 2016, BMW, buffer, I'm sure

You May Also Like

Do you have anything to post? Send it to Your Post
iGuRu about hosting and site changes
iGuRu.gr the 50 shades of gray

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « Google Earth updated & for iOS users
Next Post: Bitcoin Cash 24 hours after the third digital currency »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.