
DEF CON 32 - UDSonCAN Attacks Discovering Safety Critical Risks by Fuzzing - Seunghee Han
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 23:29
This presentation reveals safety-critical vulnerabilities in EV vehicles through UDS protocol fuzzing 0:31. Sunan from AutoCrypt discovered that diagnostic services could be exploited while vehicles are in operation.
Key Takeaways:
• Two critical vulnerabilities were found: ECU reset causing sudden stops 4:57 and communication control enabling vehicle disabling 14:26
• The vulnerabilities were demonstrated on a latest EV SUV model while driving 7:23
• Attack scenarios include sudden engine stops and complete vehicle disabling 5:05
• These services should only operate when engine is off and after security authorization 20:25
Security for diagnostic services is essential as exploiting these vulnerabilities could cause serious accidents 23:00.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
hello my name is Sunan I'm a small girl from Korea and the first author of this talk it's my first time at Devcon so I'm very nervous and so excited anyway the title of this talk is udas on canex discovering safety critical risk by fuzing in this presentation I will talk about the weak point point that I found in the latest EV models by fuding test before the presentation let me introduce ourselves we are all security researchers at autoc Crypt autoc crypt is a mobility security company nowadays we are focusing on vehicle security with the 2020 WP do 29 it's a car cyber security rules all car makers must get csms certification so we have been doing fudging tests with many oems and tier suppliers during the fing test I found some strange behavior in the car the moving car was stopped or it …