Metrics
Affected Vendors & Products
| Link | Providers |
|---|---|
| https://cwe.mitre.org/data/definitions/440.html |
|
Fri, 29 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Indian Motorcycle
Indian Motorcycle scout Bobber + Tech |
|
| Vendors & Products |
Indian Motorcycle
Indian Motorcycle scout Bobber + Tech |
Fri, 29 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the motorcycle's anti-theft shutdown by forcing the Wireless Control Module (WCM) into the CAN bus-off state. Using a well-known CAN error-frame injection technique against a periodic WCM transmission, the attacker drives the WCM CAN controller's transmit error counter past the bus-off threshold, after which the WCM stops transmitting all messages, including the shutdown command. Peer ECUs do not interpret WCM silence as a security event and continue normal operation, allowing the motorcycle to be operated despite the immobilizer never having been unlocked. Specific protocol details have been withheld pending vendor remediation. | |
| Title | Indian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft shutdown | |
| Weaknesses | CWE-440 CWE-693 CWE-754 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ASRG
Published:
Updated: 2026-05-29T15:26:58.445Z
Reserved: 2026-05-29T07:26:43.198Z
Link: CVE-2026-49316
Updated: 2026-05-29T15:26:55.163Z
Status : Deferred
Published: 2026-05-29T14:16:32.480
Modified: 2026-05-29T15:11:03.853
Link: CVE-2026-49316
No data.
OpenCVE Enrichment
Updated: 2026-05-29T16:00:15Z