← Volver a CVEs
CVE-2023-33281
MEDIUM6.5
Descripcion
The remote keyfob system on Nissan Sylphy Classic 2021 sends the same RF signal for each door-open request, which allows for a replay attack. NOTE: the vendor's position is that this cannot be reproduced with genuine Nissan parts: for example, the combination of keyfob and door handle shown in the exploit demonstration does not match any technology that Nissan provides to customers.
Detalles CVE
Puntuacion CVSS v3.16.5
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vector de ataqueADJACENT_NETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado5/22/2023
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
nissan:sylphy_classic_2021nissan:sylphy_classic_2021_firmware
Debilidades (CWE)
CWE-294
Referencias
https://twitter.com/Kevin2600/status/1658059570806415365(cve@mitre.org)
https://www.youtube.com/watch?v=GG1utSdYG1k(cve@mitre.org)
https://chaos-lab.blogspot.com/2023/05/nissan-sylphy-classic-2021-fixed-code.html(af854a3a-2127-422b-91ae-364da2661108)
https://twitter.com/Kevin2600/status/1658059570806415365(af854a3a-2127-422b-91ae-364da2661108)
https://www.youtube.com/watch?v=GG1utSdYG1k(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.