Acrisure KARR BT and DR-100
Summary
A vulnerability in Acrisure KARR BT and DR-100 systems allows attackers to issue unauthorized commands to vehicles by exploiting a shared Bluetooth authentication key. Successful exploitation could lead to unauthorized access to vehicle functions like door unlocking and engine immobilization.
IFF Assessment
This vulnerability allows attackers to gain unauthorized control over vehicle functions, posing a direct threat to safety and security.
Severity
The CVSS score of 8.1 indicates a high severity. The vulnerability involves the use of a hard-coded cryptographic key, allowing for remote attacks with significant impact on the confidentiality, integrity, and availability of vehicle control.
Defender Context
This vulnerability highlights the risks associated with hard-coded cryptographic keys in connected vehicle systems, particularly those involving Bluetooth communication. Defenders should monitor for potential exploits targeting automotive anti-theft systems and ensure timely patching of affected devices. The widespread deployment across transportation sectors means a successful attack could have significant impact.