CVE-2022-27254
MEDIUM 5.3EPSS 1.0%
The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows for a replay attack, a related issue to CVE-2019-20626.
- CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N - CVSS v2.0
- 2.9 LOW
AV:A/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 1.04% chance of exploitation in the next 30 days, 62th percentile
- Published
- 2022-03-23
- Updated
- 2024-08-03
Proof-of-concept exploits (5)
- nonamecoder/CVE-2022-27254460★ · 2022-03-26
- https://news.ycombinator.com/item?id=30804702
- https://www.bleepingcomputer.com/news/security/honda-bug-lets-a-hacker-unlock-and-start-y…
- https://www.theregister.com/2022/03/25/honda_civic_hack/
- SuryaN03/DOS-REMOTE-POC0★ · 2022-04-18