Description
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack. Manufacture is unknown at the time of release. CVE Record will be updated once this is clarified.
Problem types
CWE-307 Improper Restriction of Excessive Authentication Attempts
CWE-294 Authentication Bypass by Capture-replay
Product status
KIA Ecuador Key Fobs version 2022/2023
Credits
Danilo Erazo
References
revers3everything.com/...iting-learning-codes-from-key-fobs/
asrg.io/...generic-smart-keyless-entry-system-replay-attack/