CVE-2024-6347

* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Altima (2022) allows attackers to trigger denial-of-service (DoS) by unauthorized access to the ECU's programming session. * No preconditions implemented for ECU management functionality through UDS session in the Blind Spot Detection Sensor ECU in Nissan Altima (2022) allows attackers to disrupt normal ECU operations by triggering a control command without authentication.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nissan-global:blind_spot_detection_sensor_ecu_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nissan-global:altima:2022:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-08-15 15:15

Updated : 2024-08-16 14:33


NVD link : CVE-2024-6347

Mitre link : CVE-2024-6347

CVE.ORG link : CVE-2024-6347


JSON object : View

Products Affected

nissan-global

  • altima
  • blind_spot_detection_sensor_ecu_firmware
CWE
CWE-285

Improper Authorization

CWE-306

Missing Authentication for Critical Function

NVD-CWE-noinfo