Skip to content

Update: Automotive Security #1984

@kamilgrzela

Description

@kamilgrzela

What is missing or needs to be updated?

I can propose an updated description for the Top 10 Automotive Security Vulnerabilities. Based on my knowledge, I believe I can add more value to this cheat sheet.

How should this be resolved?

I propose adding the following vulnerabilities:

  1. Lack of firmware/software integrity – this means that the solution does not implement Secure Boot, authenticated boot, or run-time boot verification.
  2. Lack of data storage encryption (Secure Storage) – this allows an attacker to extract sensitive data from the ECU. Physical access to the ECU is required.
  3. Lack of system input validation.

I also propose replacing:
“Weak Vehicle Communication Protocols” with “Lack of secure communication.”
The CAN protocol itself is not weak, but it does not provide any built-in security mechanisms. However, an OEM may require SecOC, which adds integrity checking for each CAN frame.

I also propose extending the description of the existing cheat sheet and adding a MITIGATION proposal.

Metadata

Metadata

Assignees

Labels

ACK_OBTAINEDIssue acknowledged from core team so work can be done to fix it.UPDATE_CSIssue about the update/refactoring of a existing cheat sheet.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions