PT-2022-23693 · Mazda · Mazda Vehicles

Levente Csikor

·

Published

2022-08-24

·

Updated

2022-08-31

·

CVE-2022-36945

CVSS v3.1

6.4

Medium

VectorAV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mazda vehicles (affected versions not specified)
Description The issue concerns the Remote Keyless Entry (RKE) receiving unit, which allows remote attackers to perform unlock operations and force a resynchronization after capturing three consecutive valid key-fob signals over the radio. This is known as a RollBack attack, enabling the attacker to retain the ability to unlock indefinitely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2022-36945

Affected Products

Mazda Vehicles