CVE-2022-27254
Published on: Not Yet Published
Last Modified on: 03/31/2022 08:28:00 PM UTC
Certain versions of Civic 2018 from Honda contain the following vulnerability:
The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows for a replay attack, a related issue to CVE-2019-20626.
- CVE-2022-27254 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
ADJACENT_NETWORK | HIGH | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | HIGH | NONE |
CVSS2 Score: 2.9 - LOW
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
ADJACENT_NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
GitHub - HackingIntoYourHeart/Unoriginal-Rice-Patty: "Unoriginal-Rice-Patty" is my personal title for the Replay-based attack on Honda and Acura vehicles | github.com text/html |
![]() |
Honda bug lets a hacker unlock and start your car via replay attack | www.bleepingcomputer.com text/html |
![]() |
https://drive.google.com/file/d/1MtmWfBs1r6Y3JN1HpbNsZqO1GcsdgPdc/view?usp=sharing | drive.google.com text/html Inactive LinkNot Archived |
![]() |
GitHub - nonamecoder/CVE-2022-27254: PoC for vulnerability in Honda's Remote Keyless System(CVE-2022-27254) | github.com text/html |
![]() |
Various Honda vehicles send the same, unencrypted RF signal for each door-open | Hacker News | news.ycombinator.com text/html |
![]() |
Honda Civics vulnerable to remote unlock, start hack • The Register | www.theregister.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
PoC for vulnerability in Honda's Remote Keyless System(CVE-2022-27254)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Honda | Civic 2018 | - | All | All | All |
Operating System | Honda | Civic 2018 Firmware | - | All | All | All |
- cpe:2.3:h:honda:civic_2018:-:*:*:*:*:*:*:*:
- cpe:2.3:o:honda:civic_2018_firmware:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-27254 : The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open… twitter.com/i/web/status/1… | 2022-03-23 22:09:22 |
![]() |
GitHub - nonamecoder/CVE-2022-27254: PoC for vulnerability in Honda's Remote Keyless System(CVE-2022-27254) - github.com/nonamecoder/CV… | 2022-03-23 23:47:14 |
![]() |
github.com/nonamecoder/CV… | 2022-03-24 01:09:37 |
![]() |
CVE-2022-27254 | 2022-03-23 23:38:55 |
![]() |
Honda key fob replay attack vulnerability concerns | 2022-03-25 18:05:07 |
![]() |
Hacker News top posts: Mar 26, 2022 | 2022-03-26 13:33:13 |
![]() |
CVE-2022-27254 - Remote Keyless System Vulnerability 10th Gen | 2022-03-31 01:28:34 |
![]() |
Flipper FW for CVE-2022-27254 (Honda Civic 2018 door replay) | 2022-08-16 21:12:58 |
![]() |
Alternative for flipper zero for Honda cve-2022-27254 hack? | 2022-10-06 02:17:55 |