We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6348

Predictable seed generation after ECU reset



AssignerASRG
Reserved2024-06-26
Published2024-08-19
Updated2024-08-19

Description

Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security controls via repeated ECU resets and seed requests.



MEDIUM: 5.3CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/AU:Y/V:D/RE:H

Problem types

CWE-330: Use of Insufficiently Random Values

Product status

Default status
unaffected

Altima 2022
unknown

Credits

Thomas Sermpinis 0x4006138be0

References

https://asrg.io/security-advisories/

cve.org CVE-2024-6348

nvd.nist.gov CVE-2024-6348

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.