CVE-2018-1170: High severity htc customer-link bridge vulnerability
This vulnerability allows adjacent attackers to inject arbitrary Controller Area Network messages on vulnerable installations of Volkswagen Customer-Link App 1.30 and HTC Customer-Link Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Customer-Link App and Customer-Link Bridge. The issue results from the lack of a proper protection mechanism against unauthorized firmware updates. An attacker can leverage this vulnerability to inject CAN messages. Was ZDI-CAN-5264.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1170?
The severity of CVE-2018-1170 is high with a CVSS score of 8.8.
Which software versions are affected by CVE-2018-1170?
Vulnerable installations of Volkswagen Customer-Link App 1.30 and HTC Customer-Link Bridge are affected by CVE-2018-1170.
What is the specific flaw within CVE-2018-1170?
The specific flaw within CVE-2018-1170 allows adjacent attackers to inject arbitrary Controller Area Network (CAN) messages.
Is authentication required to exploit CVE-2018-1170?
No, authentication is not required to exploit CVE-2018-1170.
How can I fix CVE-2018-1170?
Currently, there is no known fix or patch for CVE-2018-1170. It is recommended to follow the vendor's security advisories for any updates or mitigation steps.