Hackers Could Take Control of Car Dashboard by Hacking Its Modem
ID: 512e4612-37e1-5f16-b76b-35321d36252f
STIX ID: report--512e4612-37e1-5f16-b76b-35321d36252f
Feed Name: cybersecurityNews.com
Securelist researchers identified a critical stack-based buffer overflow in the Unisoc UIS7862A modem used in many vehicle head units. By sending a single malformed 3G RLC packet with excessive optional headers, an attacker can overflow a 0xB4-byte stack buffer (packet can be up to 0x5F0 bytes), overwrite the return address, and use ROP techniques to achieve remote code execution on the modem, pivot to the application processor, patch memory protections, compromise the Android kernel, and run arbitrary applications on the car dashboard.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
