Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - In A Connected Car World; Who Has Control Of The Wheel?
Study & Research

In A Connected Car World; Who Has Control Of The Wheel?

ISBuzz TeamBy ISBuzz TeamAugust 16, 20164 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

New research paper from IOActive shows half of vehicle vulnerabilities could put hackers in the driving seat

 IOActive, the worldwide leader in research-driven security services, will be releasing the findings of a three year study into the vehicle cybersecurity space. The findings are detailed in a new research paper – Commonalities in Vehicle Vulnerabilities – which offers analysis on the general issues and potential solutions to the cybersecurity issues facing today’s connected vehicles.

The paper provides metadata analysis of real-world private vehicle security assessments, conducted by IOActive’s Vehicle Cybersecurity Division since 2013. It combines insights gleaned from 16,000 man hours of combined research and services, as well as other publicly available research. The detailed findings include stats on the impact, likelihood, overall risk and remediation of vulnerabilities, with recommendations from IOActive on how to create more secure vehicle systems in the future.

Key findings include:

  • The impact should a vulnerability be exploited:Half of the vulnerabilities uncovered would be considered ‘Critical’ (i.e. would receive media attention and have a severe impact on the vehicle) or ‘High’ impact (i.e. would have a major impact on the vehicle and could be a regulatory violation) and would result in a compromise of components, communications, or data that causes complete or partial loss of control over the vehicle
  • The likelihood that a vulnerability will be exploited:71% of the vulnerabilities uncovered were categorised as ‘Medium’ or above in relation to the likelihood of them happening – meaning at best, ‘an attacker could exploit the vulnerability without much difficulty’, at worst ‘the vulnerability is almost certain to be exploited and knowledge of the vulnerability and its exploitation are in the public domain’
  • The overall risk when combining impact and likelihood:22% of vulnerabilities sit in the ‘Critical’ camp; meaning they are both easy to discover and exploit, and can have a major impact on the vehicle
  • The impact on the vehicle of specific vulnerabilities:27% of vulnerabilities can be used to gain CANBus (Control Area Network) Access and if a hacker can get into the CANBus they can control the vehicle; a further 8% could provide ECU control (8%) or disable ECU (1%) which would allow the hacker to control everything, including all normal functionality, as well as potentially allowing them to add functionality
  • The most common attack vectors:55% of vulnerabilities are related to the network (which includes all network traffic, such as Ethernet, Web and Mobile/Cellular) and attackers are most likely to focus their efforts on the points where data enters the vehicle, such as: Cellular Radio, Bluetooth, Vehicle to Vehicle (V2V) Radio, on-board diagnostics equipment (e.g. OBDII), Wi-Fi, Infotainment Media, Zigbee Radio, and Companion Apps
  • The ability to remediate vulnerabilities:Engineering problems are the root cause of three of the top eight vulnerabilities, and they are also the most difficult to remediate. In some cases vulnerabilities stemming from design-level issues are impossible to fix, as the system is ‘insecure by design’. Problems with deployment mechanisms, process and testing also cause a number of vulnerabilities, such as backdoors, information disclosure, hardcore credentials and vulnerability dependency. Fortunately, some of these can be easier to remediate and the majority of critical impact vulnerabilities can be remediated with simple fixes – for example, patching code to remove a buffer overflow is relatively easy

Corey Thuen, Senior Security Consultant at IOActive, who authored the paper, commented: “The days when a rogue street urchin wielding a coat hanger was the main threat to vehicle security are long gone. As the report shows, we have uncovered a number of ‘hair-on-fire’ vulnerabilities that could easily be exploited at any moment – so manufacturers really need to wake up to the risks they face in the new connected world. The majority of cybersecurity vulnerabilities are not solvable using bolt-on solutions, instead relying on sound engineering, software development practices, and cybersecurity best practices. The most effective cybersecurity work occurs during the planning, design and early implementation phases of the products, with the difficulty and cost of remediation increasing in correlation with product age and complexity. Failing to address security at the early development stages could be very costly in the long-run, leading to loss of consumer confidence or even product recalls – a situation that some vehicle manufacturers would find hard to recover from.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}