PT-2024-34515 · Kia · Kia Seltos
Nitinronge91
·
Published
2024-11-22
·
Updated
2025-01-13
·
CVE-2024-51073
CVSS v3.1
6.7
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions:
KIA Seltos vehicle instrument cluster version 1.0
Description:
An issue in the KIA Seltos vehicle instrument cluster allows attackers to control or disrupt CAN communication between the instrument cluster and CAN bus. The findings are disputed by the supplier due to the potentially unrealistic test environment and because the observed behavior follows the UDS specification.
Recommendations:
For KIA Seltos vehicle instrument cluster version 1.0, consider restricting access to the CAN bus to minimize the risk of exploitation until a patch or official fix is available from the supplier.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kia Seltos