CVE-2022-37305
Last modified
CVE-2022-37305 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. The Remote Keyless Entry (RKE) receiving unit on certain Honda vehicles through 2018 allows remote attackers to perform unlock operations and force a resynchronization after capturing five consecutive valid RKE signals over the radio, aka a RollBack attack. The attacker retains the ability to unlock indefinitely.. EPSS estimates a 0.90% chance of exploitation in the next 30 days.
Description
The Remote Keyless Entry (RKE) receiving unit on certain Honda vehicles through 2018 allows remote attackers to perform unlock operations and force a resynchronization after capturing five consecutive valid RKE signals over the radio, aka a RollBack attack. The attacker retains the ability to unlock indefinitely.
Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Honda | Honda Firmware | <= 2018 |
References
- https://hackaday.com/2022/08/17/rollback-breaks-into-your-car/Exploit, Third Party Advisory
- https://www.pcmag.com/news/is-your-car-key-fob-vulnerable-to-this-simple-replay-attackPress/Media Coverage, Third Party Advisory
- https://www.youtube.com/playlist?list=PLYodcy84oQL1gxwiuRm13xRXxTQL9cO5tExploit, Third Party Advisory
- https://hackaday.com/2022/08/17/rollback-breaks-into-your-car/Exploit, Third Party Advisory
- https://www.pcmag.com/news/is-your-car-key-fob-vulnerable-to-this-simple-replay-attackPress/Media Coverage, Third Party Advisory
- https://www.youtube.com/playlist?list=PLYodcy84oQL1gxwiuRm13xRXxTQL9cO5tExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-37305?
How severe is CVE-2022-37305?
How do I fix CVE-2022-37305?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-3730A vulnerability, which was classified as critical, was found…9.8
- CVE-2022-37300A CWE-640: Weak Password Recovery Mechanism for Forgotten Pa…9.8
- CVE-2022-37301A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerabil…7.5
- CVE-2022-37302A CWE-119: Improper Restriction of Operations within the Bou…5.5
- CVE-2022-37303Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-37304Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-37306OX App Suite before 7.10.6-rev30 allows XSS via an upsell tr…6.1
- CVE-2022-37307OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a…6.1
- CVE-2022-37308OX App Suite through 7.10.6 allows XSS via HTML in text/plai…6.1
- CVE-2022-37309OX App Suite through 7.10.6 allows XSS via script code withi…6.1
- CVE-2022-3731A vulnerability has been found in seccome Ehoney and classif…9.8
- CVE-2022-37310OX App Suite through 7.10.6 allows XSS via a malicious capab…6.1
Are you affected by CVE-2022-37305?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
