漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Alps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay Attack
Vulnerability Description
Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-back attack against its rolling-code authentication.
An attacker within RF range who records two consecutive lock or unlock transmissions from a legitimate key fob can later replay the same pair of transmissions repeatedly. During testing, replaying the first captured transmission caused the RKES to enter a state in which replaying the second captured transmission resulted in a successful lock or unlock operation of the vehicle. Tested and confirmed on a 2024 Suzuki Swift (SWIFT ISG GLS AC 1.2 5P 4x2 TM).
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
使用捕获-重放进行的认证绕过
Vulnerability Title
ALPS ALPINE FCC ID CWTR53R0 授权问题漏洞
Vulnerability Description
ALPS ALPINE FCC ID CWTR53R0是日本ALPS ALPINE公司的一款用于车载或电子设备中的低功耗无线通信射频模块。 Remote Keyless Entry System (RKES) R53R0版本存在授权问题漏洞,该漏洞源于滚动码认证/再同步逻辑存在问题,可能导致攻击者通过无线电频率范围记录两次连续的锁车或解锁传输,并进行重放攻击。
CVSS Information
N/A
Vulnerability Type
N/A