Get the latest tech news

Security Flaws In Carmaker's Web Portal Let a Hacker Remotely Unlock Cars


Three years ago security researcher Eaton Zveare discovered a vulnerability in Jacuzzi's SmartTub interface allowing access to the personal data of every hot tub owner. Now Zverae says flaws in an unnamed carmaker's dealership portal "exposed the private information and vehicle data of its custom...

Three years ago security researcher Eaton Zveare discovered a vulnerability in Jacuzzi's SmartTub interface allowing access to the personal data of every hot tub owner. Zveare, who works as a security researcher at software delivery company Harness, told TechCrunch the flaw he discovered allowed the creation of a ["national"] admin account that granted "unfettered access" to the unnamed carmaker's centralized web portal. When logged in, the account granted access to more than 1,000 of the carmakers' dealers across the United States, he told TechCrunch... With access to the portal, Zveare said it was also possible to pair any vehicle with a mobile account, which allows customers to remotely control some of their cars' functions from an app, such as unlocking their cars... "The takeaway is that only two simple API vulnerabilities blasted the doors open, and it's always related to authentication," said Zveare.

Get the Android app

Or read this on Slashdot

Read more on:

Photo of hacker

hacker

Photo of carmaker

carmaker

Photo of Security flaws

Security flaws

Related news:

News photo

Security flaws in a carmaker’s web portal let one hacker remotely unlock cars from anywhere

News photo

Hacker extradited to US for stealing $3.3 million from taxpayers

News photo

Hacker used a voice phishing attack to steal Cisco customers’ personal information