License Plate Vulnerabilities Allow Remote Hacking of Kia Vehicles

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Kia Vehicle Vulnerability Exposes Remote Control Risks

In a shocking turn of events, millions of Kia vehicles were discovered to have a critical flaw that allowed attackers to remotely control the vehicles using just license plate information. This vulnerability was brought to light by independent security researchers who alerted Kia to the issue in mid-August.

The flaw, similar to others discovered in recent years, raised serious concerns about the susceptibility of modern connected vehicles to cyberattacks. Researchers, including Sam Curry, found that attackers could exploit the flaw to issue commands for locking and unlocking vehicles, starting and shutting down the engine, activating headlights and horns, and even accessing a vehicle’s camera.

The issue stemmed from a vulnerability in the automotive API protocols that enable Internet-to-vehicle commands on Kia automobiles. By registering a Kia dealer account and authenticating it, attackers could access APIs reserved for dealers, allowing them to control key vehicle functions. They could remotely lock and unlock vehicles, activate headlights and horns, determine geolocation, and even retrieve the owner’s personally identifying information.

Experts in cybersecurity emphasize the need for automakers to enhance cybersecurity measures by implementing stronger authentication methods and securing communication channels to protect against unauthorized access. The discovery of this flaw underscores the concerning pattern of cybersecurity vulnerabilities in connected vehicles and the urgent need for greater oversight and scrutiny of automaker practices. Kia Motors has yet to respond to requests for comment on the issue.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

US Senator Requests NSA Guidance on Best Practices for VPN Use Against Foreign Surveillance

A prominent US senator is urging the National Security Agency (NSA) to provide public guidance on best practices for using virtual private networks (VPNs)...

Cisco Patches Critical Nexus 9000 Vulnerability Allowing Remote Code Execution as Root

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker...

BREEZE COMET Threat Actor Targets Brazilian Financial Sector with Sophisticated Attacks

BREEZE COMET: A Rising Threat to Brazil's Financial Sector In 2024, Mandiant began investigating a series of cyber compromises targeting Brazilian financial services, retail, and...

Dropbox Reports Compromise of 5,000 Accounts Due to Legacy Login Vulnerability

Dropbox has reported that approximately 5,000 accounts were compromised last month due to a legacy login vulnerability associated with Lenovo IDs. This breach allowed...