Get a Pentest and security assessment of your IT network.

News

Flaws in BMW ConnectedDrive Infotainment System allow remote hack

A research discovered two zero-day vulnerabilities residing in the official BMW web domain and ConnectedDrive portal that allow remote hack. The vulnerabilities are still unpatched exposing them to cyber attacks. The VIN (Vehicle Identification Number) session vulnerability resides in the session management of VIN usage and hackers could exploit it to bypass the secure validation procedures of the VIN remotely using a live session. The second vulnerability is a client-side cross-site scripting vulnerability. The vulnerability is located in the.t` value (token) of the `passwordResetOk` web-application file.”]

Source: http://securityaffairs.co/wordpress/49149/hacking/bmw-connecteddrive-hacking.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Google's Quest to Kill the Cookie Is Creating a Privacy Shitshow

News

Hackers turn their back on exploiting Java, to focus on Flash flaws