Описание
The Remote Keyless Entry (RKE) receiving unit on certain Mazda vehicles through 2020 allows remote attackers to perform unlock operations and force a resynchronization after capturing three consecutive valid key-fob signals over the radio, aka a RollBack attack. The attacker retains the ability to unlock indefinitely.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Press/Media CoverageThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Press/Media CoverageThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2020 (включая)
Одновременно
cpe:2.3:o:mazda:mazda_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mazda:mazda:-:*:*:*:*:*:*:*
EPSS
Процентиль: 81%
0.01502
Низкий
6.4 Medium
CVSS3
Дефекты
CWE-294
Связанные уязвимости
CVSS3: 6.4
github
больше 3 лет назад
The Remote Keyless Entry (RKE) receiving unit on certain Mazda vehicles through 2020 allows remote attackers to perform unlock operations and force a resynchronization after capturing three consecutive valid key-fob signals over the radio, aka a RollBack attack. The attacker retains the ability to unlock indefinitely.
EPSS
Процентиль: 81%
0.01502
Низкий
6.4 Medium
CVSS3
Дефекты
CWE-294