Denial of Service Vulnerability in KIA Seltos Vehicle Instrument Cluster
CVE-2024-51072

5.3MEDIUM

Key Information:

Vendor

KIA

Vendor
CVE Published:
22 November 2024

What is CVE-2024-51072?

A vulnerability has been identified in the KIA Seltos vehicle instrument cluster, primarily linked to software and hardware version 1.0. This issue could allow attackers to execute a Denial of Service (DoS) by exploiting the ECU reset UDS service. It is important to note that the supplier has contested these findings, citing that they originated from an unrealistic testing scenario utilizing an isolated ECU that was not in a vehicle. Additionally, the ECUReset specification does not mandate manufacturers to implement Security Access and Authentication, further complicating the situation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.