Post by NoddyPost by Keithr0It's the manufacturers software.
https://arstechnica.com/cars/2024/09/flaw-in-kia-web-portal-let-
researchers-track-hack-cars/
Stupid bugs, but it doesn't allow people to do much other than make
pests of themselves.
Uh oh, Darren is a software engineer now! But, just like his imagined
expertise in the automotive field, his lack of insight is just as
visible here as well.
For instance, did you bother to access the *link* within the link above?
This one; https://samcurry.net/web-hackers-vs-the-auto-industry
Findings Summary
Vulnerability Writeups
(1) Full Account Takeover on BMW and Rolls Royce via
Misconfigured SSO
(2) Remote Code Execution and Access to Hundreds of
Internal Tools on Mercedes-Benz and Rolls Royce
via Misconfigured SSO
(3) Full Account Takeover on Ferrari and Arbitrary
Account Creation allows Attacker to Access,
Modify, and Delete All Customer Information and
Access Administrative CMS Functionality to
Manage Ferrari Websites
(4) SQL Injection and Regex Authorization Bypass on
Spireon Systems allows Attacker to Access, Track,
and Send Arbitrary Commands to 15 million
Telematics systems and Additionally Fully Takeover
Fleet Management Systems for Police Departments,
Ambulance Services, Truckers, and Many Business
Fleet Systems
(5) Mass Assignment on Reviver allows an Attacker to
Remotely Track and Overwrite the Virtual License
Plates for All Reviver Customers, Track and
Administrate Reviver Fleets, and Access, Modify,
and Delete All User Information
(6) Full Remote Vehicle Access and Full Account
Takeover affecting Hyundai and Genesis
(7) Full Remote Vehicle Access and Full Account
Takeover affecting Honda, Nissan, Infiniti, Acura
(8) Full Vehicle Takeover on Nissan via Mass Assignment
Credits
Just look at number 4 above Darren!
Fully *Takeover Fleet Management Systems* for Police Departments,
Ambulance Services, Truckers, and Many Business Fleet Systems.
These are *not* nuisance bugs.
You scan but you do not see, you read but you do not understand.
--
Xeno
Nothing astonishes Noddy so much as common sense and plain dealing.
(with apologies to Ralph Waldo Emerson)