Facebook Twitter Instagram
    Goobuntu
    • Home
    • Linux
    • Windows
    • Mobile
    • News
    Goobuntu
    Home»News»Ford Cars WiFi Vulnerability Let Attackers Execute Remote Code

    Ford Cars WiFi Vulnerability Let Attackers Execute Remote Code

    0
    By Goobuntu on August 14, 2023 News
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ford recently identified a buffer overflow flaw in the Wi-Fi driver used by it in the SYNC 3 infotainment system. After the discovery, Ford quickly alerted about this flaw and disclosed the vulnerability publicly.

    Car hijacking by hackers exploiting various functions of the car is known, but the real-world execution of such attacks remains challenging.

    While there are certain vulnerabilities that cause immediate serious consequences, enabling threat actors to open and start the cars by exploiting the vulnerabilities remotely.

    Since this system is used in the Ford and Lincoln vehicles, so, the successful exploitation of this flaw could enable threat actors to perform remote code execution.

    This vulnerability has been tracked as “CVE-2023-29468,” and it was detected by a researcher who reported this flaw to the Wi-Fi module supplier, Texas Instruments (TI).

    Document

    FREE Webinar

    API Attacks Have Increased by 400% – Understand the Fundamentals of Protecting Your APIs with a Positive Security Model – Register Now for a Free Webinar

    Flaw Profile

    • CVE ID: CVE-2023-29468
    • Summary: The TI WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_EXT_1_IE_ID or XCC_EXT_2_IE_ID that can be parsed in a management frame. Using a specially crafted frame, a buffer overflow can be triggered which can potentially lead to remote code execution.
    • TI PSIRT ID: TI-PSIRT-2022-120160
    • CVSS Score: The CVSS base score for this issue can range from 8.8 to 9.6.
    • Affected Products: WILINK8-WIFI-MCP8 version 8.5_SP3 and earlier

    Ford’s Response

    The SYNC3 infotainment system offers in-car WiFi, connectivity, voice commands, and third-party apps. The vulnerability concerns Ford customers, but no known exploits were reported. 

    Moreover, the attackers need physical proximity to an exposed, running engine with Wi-Fi enabled for a successful attack.

    Ford’s investigation concludes that this vulnerability won’t impact vehicle safety, as the infotainment system firewall prevents control interference with steering, throttling, and braking.

    Besides this, Ford assured that soon it will release the online software patch for USB installation. Meanwhile, customers who are concerned about the flaw can disable the Wi-Fi via SYNC 3’s Settings menu or check the vehicle’s SYNC 3 status online.

    Keep informed about the latest Cyber Security News by following us on GoogleNews, Linkedin, Twitter, and Facebook.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Forever 21 Systems Hacked: 500,000+ Users Affected

    September 1, 2023

    Hackers Exploit Openfire Vulnerability To Deploy Kinsing Malware

    September 1, 2023

    BadBazaar Malware Attacking Users Via Weaponized Apps

    September 1, 2023

    Leave A Reply Cancel Reply

    Popular Posts
    Forever 21 Systems Hacked: 500,000+ Users Affected
    By GoobuntuSeptember 1, 20230
    How to Fix the Action Center Not Opening in Windows
    By GoobuntuSeptember 1, 20230
    Hackers Exploit Openfire Vulnerability To Deploy Kinsing Malware
    By GoobuntuSeptember 1, 20230
    BadBazaar Malware Attacking Users Via Weaponized Apps
    By GoobuntuSeptember 1, 20230
    © 2023 Goobuntu. All Rights Reserved Goobuntu.
    • Contact Us
    • Privacy Policy
    • DMCA
    • Sitemap

    Type above and press Enter to search. Press Esc to cancel.