Major Bluetooth Vulnerabilities Exposed in Automotive Systems
Cybersecurity experts have unveiled serious vulnerabilities in OpenSynergy’s BlueSDK Bluetooth stack that can jeopardize millions of vehicles from several leading manufacturers. Dubbed PerfektBlue, these vulnerabilities have the potential to facilitate remote code execution, creating significant concerns for vehicle security.
What is PerfektBlue?
The PerfektBlue vulnerabilities comprise four critical security flaws that can be combined into an exploit chain, enabling unauthorized code execution on the In-Vehicle Infotainment (IVI) systems of cars manufactured by well-known brands like Mercedes-Benz, Volkswagen, and Skoda. Reports also confirm that an additional unnamed vehicle manufacturer is affected by these vulnerabilities.
Technical Details of the Vulnerabilities
According to PCA Cyber Security, the exploitation of PerfektBlue hinges on several memory corruption and logical vulnerabilities within the BlueSDK. These flaws can enable attackers to launch a Remote Code Execution (RCE) attack, raising the stakes for automotive cybersecurity.
The vulnerabilities identified include:
- CVE-2024-45434: A critical Use-After-Free vulnerability in the AVRCP service (CVSS score: 8.0).
- CVE-2024-45431: A moderate flaw concerning the improper validation of a remote CID in an L2CAP channel (CVSS score: 3.5).
- CVE-2024-45433: An issue with function termination in RFCOMM (CVSS score: 5.7).
- CVE-2024-45432: An incorrect parameter in a function call within RFCOMM (CVSS score: 5.7).
How the Attack Works
A significant concern is that executing the attack requires minimal technical expertise. An attacker simply needs to be within Bluetooth range of a targeted vehicle’s infotainment system to initiate the exploitation. The process is almost akin to a single-click attack, allowing the unauthorized access to be triggered over wireless networks. The extent to which this attack is feasible can vary based on how each automotive manufacturer implements their frameworks.
Implications for Vehicle Security
Once an attacker gains access to a vehicle’s IVI system, they can perform a range of unauthorized actions. These include tracking the vehicle’s GPS location, accessing contact lists, and even infiltrating more critical vehicle functions such as engine control. The method to maintain communication with the vehicle, once compromised, can allow for extensive control over various functions.
Vulnerability Mitigation
Following a responsible disclosure in May 2024, manufacturers have rolled out security patches to address these vulnerabilities by September 2024. However, the severity of these flaws highlights the need for continuous vigilance within the automotive industry regarding cybersecurity measures.
Examples from the Field
In April 2024, PCA Cyber Security also outlined methods to remotely infiltrate a Nissan Leaf electric vehicle using similar Bluetooth vulnerabilities to take control over essential functionalities. The approach involved exploiting Bluetooth weaknesses to break into internal networks, bypassing secure boot processes for enhanced access.
Through the establishment of a Command-and-Control (C2) channel over DNS, attackers can secure ongoing remote control, tapping directly into the CAN bus. This fundamental communication protocol is vital for managing critical vehicle systems, including locks and steering functions.
The Risks of CAN Bus Exploits
The vulnerabilities related to the Controller Area Network (CAN) create an avenue for attackers with physical access to a vehicle to execute injection attacks. One notable example involves the use of small electronic devices inserted in innocuous objects, which can mimic authorized messages within the CAN bus. By doing so, these rogue devices can unlock doors or start the engine, posing a severe threat to vehicular security.
Recent Investigations
A recent report by Pen Test Partners revealed an innovative yet alarming exploit, transforming a 2016 Renault Clio into a controller for a Mario Kart game by intercepting and manipulating CAN bus data. This not only showcases the vulnerabilities present in modern automotive systems but also emphasizes the potential for creative, albeit malicious, uses of such exploits.
For vehicle owners and manufacturers alike, understanding these vulnerabilities and their implications is crucial to ensuring safety and security on the roads.


