Security vulnerabilities threaten the safety of moving vehicles

NGUYỄN ĐĂNG |

A newly discovered security vulnerability could allow bad guys to illegally access the remote control system of entire cars of a manufacturer.

This vulnerability was announced by Kaspersky cybersecurity experts on the afternoon of November 12 after a security review. By exploiting the zero-day vulnerability in a public application of a partner contractor, attackers can completely take control of the vehicle's telematics system (vehicle data collection and processing system).

This attack directly threatens the safety of the driver and passengers. For example, attackers can tie the vehicle to a gear shift or turn off the engine while moving.

Existent risks

The security assessment was conducted remotely, focusing on the manufacturer's public services and the contractor's infrastructure. Kaspersky has determined that some of its online access ports were accidentally leaked on the Internet without a full layer of security.

First, through a zero-day vulnerability of inserting malicious code into SQL commands to illegally retrieve data in the wiki application, experts extracted the contractor's user list along with hash password (one-sided encrypted version of the password and cannot be read directly).

Due to weak security policies, some of these password hash have been successfully decoded, paving the way for further penetration into the contractor's incident tracking system (this tracking system is used to manage and track tasks, errors or incidents in the project).

Notably, this system contains sensitive configuration details of the manufacturer's telematics infrastructure, including a file containing user password hash on one of the company's telematics servers.

For the connected car system, Kaspersky discovered that the fireworks were misconstructed, exposing some internal servers.

Theo cac chuyen gia, cac lo hong bao mat moi duoc phat hien nay bat nguon tu nhung van de kha pho bien trong nganh cong nghiep oto. Anh: Nhien Do
According to experts, these newly discovered security vulnerabilities stem from quite common problems in the auto industry. Photo: Nhien Do

More alarmingly, the team also discovered a firmware update, allowing the download of the edited firmware version to the telematics controller on the vehicle. This means they can access the vehicle's internal communication network, the system responsible for connecting and coordinating the operation between parts on the vehicle such as the engine and sensors.

After accessing this network, experts can affect many important functions of the vehicle such as engine control or gearbox. In real situations, if exploited, these vulnerabilities can directly threaten the safety of the driver and passengers.

Recommendation

Kaspersky recommends that contractors and technology partners in the automotive sector should:

- Limit Internet access for web services via VPNs, isolate services from the internal network of businesses

- Separate web services, so as not to be related to internal business networks

- Implement strict password policies

- Activate two-factor authentication (2FA)

- encrypt sensitive data

Integrating a logging system with the SIEM platform to track and detect incidents in real time. SIEM is an event management and security information system that helps detect unusual behavior or cyber attacks early.

For car manufacturers, cybersecurity experts recommend limiting access to the telematics platform from the vehicle's connection network, only allowing network connections on the list of permitted ones, disabling the login mechanism via SSH password, operating services with the necessary minimum authority, ensuring the authenticity of control commands sent to TCU (timatics controller on the vehicle) and integrating SIEM platform.

NGUYỄN ĐĂNG
RELATED NEWS

Tata Motors successfully patches security vulnerability to protect customer data

|

Tata Motors said it has successfully patched serious security vulnerabilities, protecting customer data and internal information from leakage.

OpenAI and Perplexity race to close security vulnerabilities in new AI browser

|

AI browsers such as ChatGPT Atlas and Comet opened the era of smart web browsing, but brought a series of unpredictable user security risks.

Hanoi will develop bus routes on the basis of BRT fast bus routes

|

In the 2030-2035 period, Hanoi will develop bus routes on the BRT express bus route and urban railway, attracting people to use public transport.

Experts talk about the issue of increasing retirement age

|

Many opinions say that it is necessary to improve the skills and productivity of young workers to promote economic growth instead of extending the retirement age.

Mr. Tran Huy Tuan was elected to hold the position of Chairman of the Ninh Binh Provincial People's Committee

|

Ninh Binh - On the afternoon of November 12, Mr. Tran Huy Tuan - Deputy Secretary of the Ninh Binh Provincial Party Committee was elected by the Provincial People's Council to hold the position of Chairman of the Provincial People's Committee with 100% of the votes.

Current status of Can Tho Stadium proposed to be relocated

|

Can Tho - After being renovated in 2019, Can Tho Stadium now has many items that are gradually deteriorating.

Da Nang discusses solutions to urgently salvage the ancient ship that was just discovered on Hoi An coast

|

The Hoi An Cultural Heritage Conservation Center and the Department of Culture, Sports and Tourism of Da Nang City discuss and find solutions to salvage and relocate ancient ships on the coast of Cam An.

U22 Vietnam beat U22 China in the opening match of Panda Cup 2025

|

On the evening of November 12, U22 Vietnam beat U22 China with a score of 1-0 in the opening match of the Panda Cup 2025.

Tata Motors successfully patches security vulnerability to protect customer data

Cát Tiên (THEO TechCrunch) |

Tata Motors said it has successfully patched serious security vulnerabilities, protecting customer data and internal information from leakage.

OpenAI and Perplexity race to close security vulnerabilities in new AI browser

Cát Tiên (Theo techcrunch) |

AI browsers such as ChatGPT Atlas and Comet opened the era of smart web browsing, but brought a series of unpredictable user security risks.

Hệ thống nội bộ của các tổ chức bị đe dọa bởi lỗ hổng bảo mật phần mềm WinRAR

SÓNG HỮU |

Hà Nội - 2 lỗ hổng bảo mật từ phần mềm WinRAR cho phép tin tặc cài cắm phần mềm độc hại, xâm nhập trái phép vào hệ thống nội bộ của các cơ quan, tổ chức.