CVE-2022-27254

Published on: Not Yet Published

Last Modified on: 03/31/2022 08:28:00 PM UTC

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Certain versions of Civic 2018 from Honda contain the following vulnerability:

The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows for a replay attack, a related issue to CVE-2019-20626.

  • CVE-2022-27254 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 5.3 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
ADJACENT_NETWORK HIGH NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE HIGH NONE

CVSS2 Score: 2.9 - LOW

Access
Vector
Access
Complexity
Authentication
ADJACENT_NETWORK MEDIUM NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE PARTIAL NONE

CVE References

Description Tags Link
GitHub - HackingIntoYourHeart/Unoriginal-Rice-Patty: "Unoriginal-Rice-Patty" is my personal title for the Replay-based attack on Honda and Acura vehicles github.com
text/html
URL Logo MISC github.com/HackingIntoYourHeart/Unoriginal-Rice-Patty
Honda bug lets a hacker unlock and start your car via replay attack www.bleepingcomputer.com
text/html
URL Logo MISC www.bleepingcomputer.com/news/security/honda-bug-lets-a-hacker-unlock-and-start-your-car-via-replay-attack/
https://drive.google.com/file/d/1MtmWfBs1r6Y3JN1HpbNsZqO1GcsdgPdc/view?usp=sharing drive.google.com
text/html
Inactive LinkNot Archived
URL Logo MISC drive.google.com/file/d/1MtmWfBs1r6Y3JN1HpbNsZqO1GcsdgPdc/view?usp=sharing
GitHub - nonamecoder/CVE-2022-27254: PoC for vulnerability in Honda's Remote Keyless System(CVE-2022-27254) github.com
text/html
URL Logo MISC github.com/nonamecoder/CVE-2022-27254
Various Honda vehicles send the same, unencrypted RF signal for each door-open | Hacker News news.ycombinator.com
text/html
URL Logo MISC news.ycombinator.com/item?id=30804702
Honda Civics vulnerable to remote unlock, start hack • The Register www.theregister.com
text/html
URL Logo MISC www.theregister.com/2022/03/25/honda_civic_hack/

Exploit/POC from Github

PoC for vulnerability in Honda's Remote Keyless System(CVE-2022-27254)

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Hardware Device InfoHondaCivic 2018-AllAllAll
Operating
System
HondaCivic 2018 Firmware-AllAllAll
  • cpe:2.3:h:honda:civic_2018:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:honda:civic_2018_firmware:-:*:*:*:*:*:*:*:

Social Mentions

Source Title Posted (UTC)
Twitter Icon @CVEreport CVE-2022-27254 : The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open… twitter.com/i/web/status/1… 2022-03-23 22:09:22
Twitter Icon @piedpiper1616 GitHub - nonamecoder/CVE-2022-27254: PoC for vulnerability in Honda's Remote Keyless System(CVE-2022-27254) - github.com/nonamecoder/CV… 2022-03-23 23:47:14
Twitter Icon @wvuuuuuuuuuuuuu github.com/nonamecoder/CV… 2022-03-24 01:09:37
Reddit Logo Icon /r/netcve CVE-2022-27254 2022-03-23 23:38:55
Reddit Logo Icon /r/Honda Honda key fob replay attack vulnerability concerns 2022-03-25 18:05:07
Reddit Logo Icon /r/hackerdigest Hacker News top posts: Mar 26, 2022 2022-03-26 13:33:13
Reddit Logo Icon /r/civic CVE-2022-27254 - Remote Keyless System Vulnerability 10th Gen 2022-03-31 01:28:34
Reddit Logo Icon /r/flipperzero Flipper FW for CVE-2022-27254 (Honda Civic 2018 door replay) 2022-08-16 21:12:58
Reddit Logo Icon /r/hacking Alternative for flipper zero for Honda cve-2022-27254 hack? 2022-10-06 02:17:55
© CVE.report 2023 Twitter Nitter Twitter Viewer |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report