PT-2017-16866 · Hyundai Motor America · Blue Link
Arjun Kumar
+1
·
Published
2017-04-26
·
Updated
2019-10-09
·
CVE-2017-6054
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hyundai Motor America Blue Link versions 3.9.4 through 3.9.5
Description
A security issue was found where the application uses a hard-coded decryption password, potentially exposing sensitive user information.
Recommendations
For versions 3.9.4 and 3.9.5, consider disabling the use of the hard-coded decryption password until a patch is available.
Restrict access to sensitive user information to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blue Link