DARPA OnStar Vulnerability Analysis
ID: 00526ae4-b69d-574c-a28f-8ba632fbbf04
STIX ID: report--00526ae4-b69d-574c-a28f-8ba632fbbf04
Feed Name: NCC Research
The report documents DARPA’s reproduction of academic research showing a remote attack on a vehicle Telematics Control Unit (TCU) via its analogue fallback modem: a buffer overflow in the software modem parsing audio data could be triggered by a crafted MP3 played over a phone call to the TCU, potentially allowing control of CAN-bus-connected vehicle functions (brakes, accelerator, microphone). The write-up explains the root cause (unsafe memcpy and mismatched assumptions between TCU manufacturer and telematics service provider), demonstrates the attack vector, and recommends mitigations such as secure coding, input validation, and restricting accepted call origins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
