Vulnerability Description
The remote keyless system on Honda HR-V 2017 vehicles sends the same RF signal for each door-open request, which might allow a replay attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Honda | Hr-V 2017 Firmware | - |
| Honda | Hr-V 2017 | - |
Related Weaknesses (CWE)
References
- https://github.com/HackingIntoYourHeart/Unoriginal-Rice-PattyExploitThird Party Advisory
- https://medium.com/%40victor_14768/replay-attacks-en-autos-206481dcfee1
- https://github.com/HackingIntoYourHeart/Unoriginal-Rice-PattyExploitThird Party Advisory
- https://medium.com/%40victor_14768/replay-attacks-en-autos-206481dcfee1
FAQ
What is CVE-2019-20626?
CVE-2019-20626 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The remote keyless system on Honda HR-V 2017 vehicles sends the same RF signal for each door-open request, which might allow a replay attack.
How severe is CVE-2019-20626?
CVE-2019-20626 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20626?
Check the references section above for vendor advisories and patch information. Affected products include: Honda Hr-V 2017 Firmware, Honda Hr-V 2017.