Freemor

Freemor at

National Cyber Awareness System:

Fiat Chrysler Automobiles (FCA) Uconnect Vulnerability

07/27/2015 05:06 PM EDT


Original release date: July 27, 2015

A vulnerability affecting the Uconnect software from FCA has been reported. Exploitation of this vulnerability may allow an unauthorized user to take remote control of an affected vehicle, but the attack requires access to Sprint's cellular network, which connects FCA vehicles to the Internet. Sprint has blocked the port used for attacks. FCA and the National Highway Transportation Safety Administration (NHTSA) have also initiated a safety recall for all potentially affected Chrysler, Dodge, Jeep, and Ram models. See the NHTSA recall announcement for a complete list.

US-CERT recommends that users review ICS Alert 15-203-01 and Vulnerability Note VU#819439for more information. Uconnect users are encouraged to review the NHTSA recall announcement and apply the software update.

lnxwalt@microca.st likes this.

@freemor@identi.ca relevant links:

http://www-odi.nhtsa.dot.gov/acms/cs/jaxrs/download/doc/UCM483033/RCAK-15V461-4967.pdf

https://ics-cert.us-cert.gov/alerts/ICS-ALERT-15-203-01

http://www.driveuconnect.com/software-update/

Freemor at 2015-07-27T23:10:56Z