PT-2017-16864 · Hyundai Motor America · Blue Link
Published
2017-04-26
·
Updated
2019-10-09
·
CVE-2017-6052
CVSS v2.0
4.3
Medium
| Vector | AV:A/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Hyundai Motor America Blue Link versions 3.9.4 through 3.9.5
Description
A Man-in-the-Middle issue was discovered, where communication channel endpoints are not verified. This may allow a remote attacker to access or influence communications between the identified endpoints.
Recommendations
For versions 3.9.4 and 3.9.5, consider restricting access to the communication channel until a patch is available. As a temporary workaround, verify the identity of endpoints before establishing communication to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blue Link