logo

CERT: Aftermarket Add-On Opens Cars To Life Threatening Hacks

ID: e21de7e1-7a98-508d-8e45-0a36caff2a77

STIX ID: report--e21de7e1-7a98-508d-8e45-0a36caff2a77

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2016-04-08

Date Updated: 2026-05-06

Author: Paul Roberts

...
...

Carnegie Mellon CERT warned that the BlueDriver aftermarket OBD-II Bluetooth device does not require a PIN, allowing nearby attackers or a compromised in-car device to create a serial connection to the vehicle CAN bus and send arbitrary commands that could affect safety-critical functions (braking, steering); CERT reported no known patch and recommended owners not operate vehicles with the device attached.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.