Acrisure KARR BT and DR-100

Summary

A vulnerability in Acrisure KARR BT and DR-100 systems allows attackers to issue unauthorized commands to vehicles by exploiting a shared Bluetooth authentication key. Successful exploitation could lead to unauthorized access to vehicle functions like door unlocking and engine immobilization.

IFF Assessment

FOE

This vulnerability allows attackers to gain unauthorized control over vehicle functions, posing a direct threat to safety and security.

Severity

8.1 High

The CVSS score of 8.1 indicates a high severity. The vulnerability involves the use of a hard-coded cryptographic key, allowing for remote attacks with significant impact on the confidentiality, integrity, and availability of vehicle control.

Defender Context

This vulnerability highlights the risks associated with hard-coded cryptographic keys in connected vehicle systems, particularly those involving Bluetooth communication. Defenders should monitor for potential exploits targeting automotive anti-theft systems and ensure timely patching of affected devices. The widespread deployment across transportation sectors means a successful attack could have significant impact.

Read Full Story →