Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security controls via repeated ECU resets and seed requests.
References
History

Tue, 20 Aug 2024 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Nissan-global
Nissan-global altima
Nissan-global blind Spot Protection Sensor Ecu Firmware
CPEs cpe:2.3:h:nissan-global:altima:2022:*:*:*:*:*:*:*
cpe:2.3:o:nissan-global:blind_spot_protection_sensor_ecu_firmware:-:*:*:*:*:*:*:*
Vendors & Products Nissan-global
Nissan-global altima
Nissan-global blind Spot Protection Sensor Ecu Firmware
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 19 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
Description Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security controls via repeated ECU resets and seed requests.
Title Predictable seed generation after ECU reset
Weaknesses CWE-330
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/AU:Y/V:D/RE:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASRG

Published: 2024-08-19T15:12:25.216Z

Updated: 2024-08-19T19:26:54.514Z

Reserved: 2024-06-26T10:31:26.483Z

Link: CVE-2024-6348

cve-icon Vulnrichment

Updated: 2024-08-19T19:26:48.546Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-19T16:15:08.973

Modified: 2024-08-20T16:17:03.810

Link: CVE-2024-6348

cve-icon Redhat

No data.