Lucene search

K
cveASRGCVE-2024-6347
HistoryAug 15, 2024 - 3:15 p.m.

CVE-2024-6347

2024-08-1515:15:22
CWE-285
CWE-306
ASRG
web.nvd.nist.gov
27
nissan altima
blind spot detection sensor
ecu
uds
dos
unauthorized access.

CVSS3

6.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS4

5.3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/SC:L/VI:L/SI:L/VA:L/SA:L/AU:Y/V:D/RE:H

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

13.3%

  • Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Altima (2022) allows attackers to trigger denial-of-service (DoS) by unauthorized access to the ECU’s programming session.
  • No preconditions implemented for ECU management functionality through UDS session in the Blind Spot Detection Sensor ECU in Nissan Altima (2022) allows attackers to disrupt normal ECU operations by triggering a control command without authentication.

Affected configurations

Nvd
Node
nissan-globalblind_spot_detection_sensor_ecu_firmwareMatch-
AND
nissan-globalaltimaMatch2022
VendorProductVersionCPE
nissan-globalblind_spot_detection_sensor_ecu_firmware-cpe:2.3:o:nissan-global:blind_spot_detection_sensor_ecu_firmware:-:*:*:*:*:*:*:*
nissan-globalaltima2022cpe:2.3:h:nissan-global:altima:2022:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "modules": [
      "Blind Spot Protection Sensor"
    ],
    "packageName": "ECU",
    "product": "Altima",
    "vendor": "Nissan",
    "versions": [
      {
        "status": "unknown",
        "version": "Altima 2022"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS4

5.3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/SC:L/VI:L/SI:L/VA:L/SA:L/AU:Y/V:D/RE:H

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

13.3%

Related for CVE-2024-6347