PT-2024-34514 · Kia · Kia Seltos
Nitinronge91
·
Published
2024-11-22
·
Updated
2025-01-10
·
CVE-2024-51072
CVSS v3.1
5.3
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
KIA Seltos vehicle instrument cluster software version 1.0
KIA Seltos vehicle instrument cluster hardware version 1.0
Description:
The issue allows attackers to cause a Denial of Service (DoS) via ECU reset UDS service. It is noted that the findings came from a potentially unrealistic test environment and the ECUReset specification does not allow a manufacturer to require SecurityAccess and Authentication.
Recommendations:
For KIA Seltos vehicle instrument cluster software version 1.0, consider disabling the ECU reset UDS service as a temporary workaround until a patch is available.
For KIA Seltos vehicle instrument cluster hardware version 1.0, restrict access to the ECU reset functionality to minimize the risk of exploitation.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kia Seltos