Vulnerability Description
Unspecified vulnerability in Uconnect before 15.26.1, as used in certain Fiat Chrysler Automobiles (FCA) from 2013 to 2015 models, allows remote attackers in the same cellular network to control vehicle movement, cause human harm or physical damage, or modify dashboard settings via vectors related to modification of entertainment-system firmware and access of the CAN bus due to insufficient "Radio security protection," as demonstrated on a 2014 Jeep Cherokee Limited FWD.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fca | Uconnect | <= 15.26.1 |
References
- http://blog.fcanorthamerica.com/2015/07/22/unhacking-the-hacked-jeep/
- http://media.fcanorthamerica.com/newsrelease.do?id=16827&mid=1
- http://www-odi.nhtsa.dot.gov/acms/cs/jaxrs/download/doc/UCM483033/RCAK-15V461-49Third Party AdvisoryUS Government Resource
- http://www-odi.nhtsa.dot.gov/acms/cs/jaxrs/download/doc/UCM483036/RCLRPT-15V461-
- http://www.securityfocus.com/bid/75993
- http://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/
- https://ics-cert.us-cert.gov/advisories/ICSA-15-260-01
- https://twitter.com/0xcharlie/status/623171594349842433
- https://twitter.com/0xcharlie/status/623195051296993280
- https://twitter.com/0xcharlie/status/623258479730552832
- https://www.youtube.com/watch?v=MK0SrxBC1xs&feature=youtu.be
- http://blog.fcanorthamerica.com/2015/07/22/unhacking-the-hacked-jeep/
- http://media.fcanorthamerica.com/newsrelease.do?id=16827&mid=1
- http://www-odi.nhtsa.dot.gov/acms/cs/jaxrs/download/doc/UCM483033/RCAK-15V461-49Third Party AdvisoryUS Government Resource
- http://www-odi.nhtsa.dot.gov/acms/cs/jaxrs/download/doc/UCM483036/RCLRPT-15V461-
FAQ
What is CVE-2015-5611?
CVE-2015-5611 is a vulnerability with a CVSS score of 8.3 (HIGH). Unspecified vulnerability in Uconnect before 15.26.1, as used in certain Fiat Chrysler Automobiles (FCA) from 2013 to 2015 models, allows remote attackers in the same cellular network to control vehic...
How severe is CVE-2015-5611?
CVE-2015-5611 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5611?
Check the references section above for vendor advisories and patch information. Affected products include: Fca Uconnect.