CVE-2015-5611
Summary
| CVE | CVE-2015-5611 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-07-21 21:05:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Unspecified vulnerability in Uconnect before 15.26.1, as used in certain Fiat Chrysler Automobiles (FCA) from 2013 to 2015 models, allows remote attackers in the same cellular network to control vehicle movement, cause human harm or physical damage, or modify dashboard settings via vectors related to modification of entertainment-system firmware and access of the CAN bus due to insufficient "Radio security protection," as demonstrated on a 2014 Jeep Cherokee Limited FWD. |
Risk And Classification
Primary CVSS: v2.0 8.3 from [email protected]
AV:A/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:A/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Unhacking the hacked Jeep® SUV | FCA North America Corporate Blog | af854a3a-2127-422b-91ae-364da2661108 | blog.fcanorthamerica.com | |
| Charlie Miller on Twitter: "This update might not sound particularly important, but trust me, if you can, you really should install this one. http://t.co/qhTCrBIho8" | af854a3a-2127-422b-91ae-364da2661108 | twitter.com | |
| FCA US LLC Releases Software Update to Improve Vehicle Electronic Security and Communications System Enhancements | af854a3a-2127-422b-91ae-364da2661108 | media.fcanorthamerica.com | |
| Attempting to access Safercar.gov interactive functions | af854a3a-2127-422b-91ae-364da2661108 | www-odi.nhtsa.dot.gov | Third Party Advisory, US Government Resource |
| Attempting to access Safercar.gov interactive functions | af854a3a-2127-422b-91ae-364da2661108 | www-odi.nhtsa.dot.gov | |
| Harman-Kardon Uconnect Vulnerability | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | |
| Charlie Miller on Twitter: "@SushiDude @nudehaberdasher there is no ota patching here, customer has to do stuff :(" | af854a3a-2127-422b-91ae-364da2661108 | twitter.com | |
| Hackers Remotely Kill a Jeep on the Highway—With Me in It - YouTube | af854a3a-2127-422b-91ae-364da2661108 | www.youtube.com | |
| Hackers Remotely Kill a Jeep on the Highway—With Me in It | WIRED | af854a3a-2127-422b-91ae-364da2661108 | www.wired.com | |
| Uconnect CVE-2015-5611 Remote Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Charlie Miller on Twitter: "Checked patch, looks good. Well done Chrysler! Now, back to a vulnerable version for more testing! http://t.co/RdBOyrRPuc" | af854a3a-2127-422b-91ae-364da2661108 | twitter.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.