漏洞概述 漏洞名称: Indian Scout 2025: Infotainment-to-WCM weak authentication allows PIN recovery CVE ID: CVE-2026-49322 发布日期: May 29, 2026 问题类型: CWE-1390 Weak Authentication CAPEC ID: CAPEC-97 Cryptanalysis 影响范围 受影响产品: Indian Motorcycle (Polaris Inc.) Scout Bobber + Tech, 2025 model year 具体模块: Wireless Control Module (WCM), Infotainment / Digital Round 修复方案 推荐修复措施: Replace the non-cryptographic response computation with a digital signature (for example ECDSA P-256) or an HMAC over a fresh per-session random nonce, bound to a stable per-vehicle identifier to prevent cross-bike replay. 参考链接 Reporter: Scott Sheahan, Rustic Security LLC CWE-1390: https://cwe.mitre.org/data/definitions/1390.html CWE-327: https://cwe.mitre.org/data/definitions/327.html CWE-294: https://cwe.mitre.org/data/definitions/294.html CAPEC-97: https://capec.mitre.org/data/definitions/97.html CAPEC-114: https://capec.mitre.org/data/definitions/114.html 时间线 2025-03-26: Reported to Indian Motorcycle (Polaris Inc.) by Rustic Security LLC under responsible disclosure 2026-05-29: Public disclosure by ASRG 其他信息 CVSS 3.1: 4.3 CVSS 4.0: 4.1 页脚信息 ASRG: Automotive Security Research Group, advancing vehicle cybersecurity through open collaboration, research, and community. Quick Links: Mission & Vision, Team, Board Advisory, History, Press Resources: Research, Academia, Disclosure, Sponsors Community: Join ASRG, Ecosystem, Contact 隐私政策与条款 Privacy policy: [链接] Terms of use: [链接] 代码块 页面中未包含POC代码或利用代码。