CVE-2024-51073

medium

Description

An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to control or disrupt CAN communication between the instrument cluster and CAN bus. NOTE: this is disputed by the Supplier because the findings came from a potentially unrealistic test environment (an isolated ECU part that was not in a vehicle), and because the observed behavior follows the UDS (Unified Diagnostic Services) specification.

References

https://www.iso.org/standard/77323.html

https://udsoncan.readthedocs.io/en/latest/udsoncan/services.html

https://github.com/nitinronge91/KIA-SELTOS-Cluster-Vulnerabilities/blob/3755e3f692dce5b1ab06de2d04a2433c907ab21c/CVE/Control%20CAN%20communication%20for%20KIA%20SELTOS%20Cluster%20CVE-2024-51073.md

Details

Source: Mitre, NVD

Published: 2024-11-22

Updated: 2025-01-13

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.7

Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H

Severity: Medium