CVE-2015-5611
Last modified
CVE-2015-5611 is a vulnerability of currently unknown severity. Unspecified vulnerability in Uconnect before 15.26.1, as used in certain Fiat Chrysler Automobiles (FCA) from 2013 to 2015 models, allows remote attackers in the same cellular network to control vehicle movement, cause human harm or physical damage, or modify dashboard settings via vectors related to modification of entertainment-system firmware and access of the CAN bus due to insufficient "Radio security protection," as demonstrated on a 2014 Jeep Cherokee Limited FWD.. EPSS estimates a 1.77% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in Uconnect before 15.26.1, as used in certain Fiat Chrysler Automobiles (FCA) from 2013 to 2015 models, allows remote attackers in the same cellular network to control vehicle movement, cause human harm or physical damage, or modify dashboard settings via vectors related to modification of entertainment-system firmware and access of the CAN bus due to insufficient "Radio security protection," as demonstrated on a 2014 Jeep Cherokee Limited FWD.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fca | Uconnect | <= 15.26.1 |
References
- http://www-odi.nhtsa.dot.gov/acms/cs/jaxrs/download/doc/UCM483033/RCAK-15V461-4967.pdfThird Party Advisory, US Government Resource
- http://www-odi.nhtsa.dot.gov/acms/cs/jaxrs/download/doc/UCM483033/RCAK-15V461-4967.pdfThird Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-5611?
How severe is CVE-2015-5611?
How do I fix CVE-2015-5611?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-5605The regular-expression implementation in Google V8, as used …
- CVE-2015-5606Vordel XML Gateway (acquired by Axway) version 7.2.2 could a…
- CVE-2015-5607Cross-site request forgery in the REST API in IPython 2 and …
- CVE-2015-5608Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4…
- CVE-2015-5609Absolute path traversal vulnerability in the Image Export pl…
- CVE-2015-5610The RSM (aka RSMWinService) service in SolarWinds N-Able N-C…
- CVE-2015-5612Cross-site scripting (XSS) vulnerability in October CMS buil…
- CVE-2015-5613Cross-site scripting (XSS) vulnerability in October CMS buil…
- CVE-2015-5614Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-5615Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-5617SQL injection vulnerability in pub/m_pending_news/delete_pen…9.8
- CVE-2015-5618Chiyu BF-630 and BF-630W fingerprint access-control devices …
Are you affected by CVE-2015-5611?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
