PT-2018-10759 · Htc+1 · Htc Customer-Link Bridge+1

Aaron Luo

+1

·

Published

2018-02-27

·

Updated

2020-08-28

·

CVE-2018-1170

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Volkswagen Customer-Link App version 1.30 HTC Customer-Link Bridge (affected versions not specified)
Description This issue allows adjacent attackers to inject arbitrary Controller Area Network messages on vulnerable installations. Authentication is not required to exploit this issue. The specific flaw exists within the Customer-Link App and Customer-Link Bridge, resulting from the lack of a proper protection mechanism against unauthorized firmware updates. An attacker can leverage this issue to inject CAN messages.
Recommendations For Volkswagen Customer-Link App version 1.30, update the protection mechanism to prevent unauthorized firmware updates. For HTC Customer-Link Bridge, implement proper protection against unauthorized firmware updates to prevent CAN message injection. As a temporary workaround, consider restricting access to the firmware update mechanism in both the Customer-Link App and the Customer-Link Bridge until a proper fix is available.

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1170
ZDI-18-214

Affected Products

Htc Customer-Link Bridge
Volkswagen Customer-Link App