Описание
The Remote Keyless Entry (RKE) receiving unit on certain Honda vehicles through 2018 allows remote attackers to perform unlock operations and force a resynchronization after capturing five consecutive valid RKE signals over the radio, aka a RollBack attack. The attacker retains the ability to unlock indefinitely.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Press/Media CoverageThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Press/Media CoverageThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2018 (включая)
Одновременно
cpe:2.3:o:honda:honda_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:honda:honda:-:*:*:*:*:*:*:*
EPSS
Процентиль: 81%
0.01502
Низкий
6.4 Medium
CVSS3
Дефекты
CWE-294
Связанные уязвимости
CVSS3: 6.4
github
больше 3 лет назад
The Remote Keyless Entry (RKE) receiving unit on certain Honda vehicles through 2018 allows remote attackers to perform unlock operations and force a resynchronization after capturing five consecutive valid RKE signals over the radio, aka a RollBack attack. The attacker retains the ability to unlock indefinitely.
EPSS
Процентиль: 81%
0.01502
Низкий
6.4 Medium
CVSS3
Дефекты
CWE-294