Metrics
Affected Vendors & Products
Mon, 13 Jan 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to arbitrarily change odometer readings in the vehicle by targeting the instrument cluster through the unsecured CAN network. NOTE: this is disputed by the supplier because the CAN bus is not externally exposed, and because the packets can only increase the odometer reading (which has no value to an adversary). | Incorrect access control in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to arbitrarily change odometer readings in the vehicle by targeting the instrument cluster through the unsecured CAN network. NOTE: this is disputed by the supplier because the CAN bus is not externally exposed, and because the packets can only increase the odometer reading (which typically has no value to an adversary). Also, this is disputed by the Supplier because the findings came from a potentially unrealistic test environment (an isolated ECU part that was not in a vehicle), and because the observed behavior follows the UDS (Unified Diagnostic Services) specification. |
Mon, 06 Jan 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to arbitrarily change odometer readings in the vehicle by targeting the instrument cluster through the unsecured CAN network. | Incorrect access control in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to arbitrarily change odometer readings in the vehicle by targeting the instrument cluster through the unsecured CAN network. NOTE: this is disputed by the supplier because the CAN bus is not externally exposed, and because the packets can only increase the odometer reading (which has no value to an adversary). |
Mon, 25 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 25 Nov 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in KIA Seltos vehicle cluster (software and hardware v1.0) allows attackers to arbitrarily change odometer readings in the vehicle by targeting the instrument cluster through the unsecured CAN network. | Incorrect access control in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to arbitrarily change odometer readings in the vehicle by targeting the instrument cluster through the unsecured CAN network. |
Mon, 25 Nov 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in Instrument Cluster KIA Seltos Software v1.0, Hardware v1.0 allows attackers to arbitrarily change odometer readings in the vehicle. | Incorrect access control in KIA Seltos vehicle cluster (software and hardware v1.0) allows attackers to arbitrarily change odometer readings in the vehicle by targeting the instrument cluster through the unsecured CAN network. |
Fri, 22 Nov 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in Instrument Cluster KIA Seltos Software v1.0, Hardware v1.0 allows attackers to arbitrarily change odometer readings in the vehicle. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-13T14:45:45.797Z
Reserved: 2024-10-28T00:00:00.000Z
Link: CVE-2024-51074
Updated: 2024-11-25T20:33:59.915Z
Status : Deferred
Published: 2024-11-22T16:15:33.860
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-51074
No data.
OpenCVE Enrichment
No data.