CVE-2016-2354 - CERT CVE
ID CVE-2016-2354
Sažetak The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without a PIN, which allows remote attackers to send arbitrary CAN commands by leveraging access to a device inside or adjacent to the vehicle, as demonstrated by a CAN command to disrupt braking or steering.
Reference
CVSS
Base: 8.0
Impact: 9.5
Exploitability:6.5
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL COMPLETE COMPLETE
CVSS vektor AV:A/AC:L/Au:N/C:P/I:C/A:C
Zadnje važnije ažuriranje 31-05-2016 - 15:13
Objavljeno 22-04-2016 - 00:59