RSS   Vulnerabilities for 'Icar 2 wi-fi obd2 firmware'   RSS

2018-05-30
 
CVE-2018-11478

CWE-287
 

 
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and debug information from the car. This on-board diagnostics feature can also be used to send commands to the car (different for every vendor / car product line / car). No authentication is needed, which allows attacks from the local Wi-Fi network.

 
 
CVE-2018-11477

CWE-319
 

 
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or Android application and the OBD dongle are not encrypted. The combination of this vulnerability with the lack of wireless network protection exposes all transferred car data to the public.

 
 
CVE-2018-11476

CWE-306
 

 
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The dongle opens an unprotected wireless LAN that cannot be configured with encryption or a password. This enables anyone within the range of the WLAN to connect to the network without authentication.

 


Copyright 2024, cxsecurity.com

 

Back to Top