Get a Pentest and security assessment of your IT network.

News

Flaws in BMW ConnectedDrive Infotainment System allow remote hack

A research discovered two zero-day vulnerabilities residing in the official BMW web domain and ConnectedDrive portal that allow remote hack. The vulnerabilities are still unpatched exposing them to cyber attacks. The VIN (Vehicle Identification Number) session vulnerability resides in the session management of VIN usage and hackers could exploit it to bypass the secure validation procedures of the VIN remotely using a live session. The second vulnerability is a client-side cross-site scripting vulnerability. The vulnerability is located in the.t` value (token) of the `passwordResetOk` web-application file.”]

Source: http://securityaffairs.co/wordpress/49149/hacking/bmw-connecteddrive-hacking.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Take note, next week update Adobe Reader and Acrobat to fix critical flaws

News

NSA-linked Cisco exploit poses bigger threat than previously thought