By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
BeFirsTrankBeFirsTrank
  • Home
  • Car Reviews
  • Auto Shows
  • Bike Reviews
  • Future
  • New Car
  • Used Car
  • Contact Us !
Reading: Tencent Keen Security Lab Uncover Vulnerabilities in BMW Connected Car, Receives Award
Share
Aa
Aa
BeFirsTrankBeFirsTrank
  • Home
  • Car Reviews
  • Auto Shows
  • Bike Reviews
  • Future
  • New Car
  • Used Car
  • Contact Us !
Search
  • Home
  • Car Reviews
  • Auto Shows
  • Bike Reviews
  • Future
  • New Car
  • Used Car
  • Contact Us !
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
BeFirsTrank > Future > Tencent Keen Security Lab Uncover Vulnerabilities in BMW Connected Car, Receives Award
Future

Tencent Keen Security Lab Uncover Vulnerabilities in BMW Connected Car, Receives Award

Loknath Das
Last updated: 2018/06/04 at 11:05 AM
By Loknath Das 4 Min Read
Share
SHARE

Tencent Keen Security Lab Uncover Vulnerabilities in BMW Connected Car, Receives Award

Many connected vehicles on the road today suffer from vulnerabilities that have not been discovered by hackers and cybersecurity specialists. German automaker BMW is currently in the process of addressing such challenges through third-party testing and research.

In a collaborative project with Chinese researchers from Tencent Keen Security Lab, the car manufacturer was able to expose several harmful exploits plaguing its line of luxury vehicles. A total of 14 hacks were discovered by the researchers. The vulnerabilities targeted infotainment systems, wireless communication components and telematics controls.

Vulnerabilities and Exploits

During the project, the researchers used different attack vectors to achieve their goals. Interestingly, only four methods required criminals to have physical access to the USB ports of the vehicle. Another four vulnerabilities exploited the car’s computer, which also required physical access by hackers.

Surprisingly, six methods focused on remote access to the unit’s internal systems. Such hacking techniques can lead to the exploitation of secure and isolated system components.

“Our research findings have proved that it is feasible to gain local and remote access to infotainment, T-Box components, and UDS communication above certain speed [for] selected BMW vehicle modules and been able to gain control of the CAN buses with the execution of arbitrary, unauthorized diagnostic requests of BMW in-car systems remotely,” said researchers from Tencent’s Keen Security Lab.

Taking the attacks one step further, criminals could combine various vulnerabilities to create an efficient hacking strategy. Hence, it is crucial for all the findings to be patched in a timely manner.

According to BMW, third-party testing of in-car platforms is a common and crucial practice within the company. The security exercises conducted by the researchers were completed with the automaker’s cybersecurity team. Timeline for testing was from January 2017 to February 2018.

Future Updates Needed

BMW is in the process of addressing the vulnerabilities uncovered by the research group. Discussions about the exploits are currently limited, as full details of the hacks won’t be published until security updates have been rolled out. So far, only a summary has been released by the research group. The full report will be published in 2019.

“Subsequently, these upgrades were rolled out in the BMW Group backend and uploaded to the telematics control units via over the air connection. The BMW Group develops additional software updates, which as usual will be made available for customers at BMW dealerships,” said the German automaker.

It is important to note that not all BMW models are affected by the vulnerabilities. BMW vehicles affected by exploits surrounding the infotainment system includes the following: BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series and BMW 7 Series. Furthermore, BMW models manufactured from 2012 to present day are affected by vulnerabilities in the Telematics Control Unit (TCB).

Moving forward, the automaker is considering a partnership with Tencent Keen Security Lab for research and development projects related to car security and testing of autonomous vehicles. In the future, BMW plans to conduct cybersecurity tests on Google Android embedded vehicle systems and OTA update protocols.

[“Source-futurecar”]

You Might Also Like

Fire At Europe’s Biggest Sand Dune In France Amid Record Heatwave

Model Education Loans, Credit Guarantee Fund Scheme: Know Details Here

Man Shot In Face For Resisting Robbery In Delhi, Hospitalised: Police

Maruti Suzuki to Launch Multiple Electric Vehicle Models in India Starting in 2025

Read Car Reviews of the Week:

TAGGED: Award, BMW, Car, Connected, in, Keen, Lab, Receives, Security, Tencent, Uncover, Vulnerabilities
Loknath Das June 4, 2018
Share
Previous Article Automakers Having Trouble Deciding Between Boasting Semi-Autonomous Features and Safety
Next Article Fiat Chrysler Supplying Waymo With Up to 62,000 Robo Taxis

Calendar

March 2023
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Dec    

Latest Trending News

  • Rent a McLaren for Your Next Luxury Trip March 2, 2023
  • Qualities of Handicap Vehicles For Sale December 10, 2022
  • Characteristics of Electric Road Bikes October 13, 2022
  • The Advantages of Digital Marketing October 12, 2022
  • U.S. State CIOs Pursuing Faster Digital Transformation July 28, 2022
  • CES 2022 Day 1 highlights: Sony confirms PlayStation VR 2, Samsung’s $899 portable projector, and more July 25, 2022
  • Fire At Europe’s Biggest Sand Dune In France Amid Record Heatwave July 22, 2022

© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.

Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

[mc4wp_form]
Zero spam, Unsubscribe at any time.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?