PT-2024-34514 · Kia · Kia Seltos

·

CVE-2024-51072

·

Published

2024-11-22

·

Updated

2025-01-10

CVSS v3.1

5.3

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: KIA Seltos vehicle instrument cluster software version 1.0 KIA Seltos vehicle instrument cluster hardware version 1.0
Description: The issue allows attackers to cause a Denial of Service (DoS) via ECU reset UDS service. It is noted that the findings came from a potentially unrealistic test environment and the ECUReset specification does not allow a manufacturer to require SecurityAccess and Authentication.
Recommendations: For KIA Seltos vehicle instrument cluster software version 1.0, consider disabling the ECU reset UDS service as a temporary workaround until a patch is available. For KIA Seltos vehicle instrument cluster hardware version 1.0, restrict access to the ECU reset functionality to minimize the risk of exploitation.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-51072

Affected Products

Kia Seltos