High Profile Linux Vulnerability May Make Vehicles Susceptible to Cyber Attack

High Profile Linux Vulnerability May Make Vehicles Susceptible to Cyber Attack

Table of contents

On January 26th,  the research group at Qualys, an IT security provider, published a report illustrating how they succeeded to exploit a vulnerability (CVE-2021-3156) in Sudo, an open source code program that is widely used in Linux-based systems. This blog will tell you a little bit more about the vulnerability and PlaxidityX’s recommendations. 

Why Are We Bringing This Vulnerability to Your Attention?

The vulnerability, which exists in Sudo versions since 2011, potentially impacts newly introduced Linux-based ECUs, such as TCUs, ADAS systems, infotainment systems, instrument clusters, and smart gateways and could affect 10s of millions of vehicles.

What Harm Can the Vulnerability do if Exploited?     

The vulnerability, also known as Baron Samedit, is a heap overflow vulnerability that can enable privilege escalation. Privilege escalation vulnerabilities provide unauthorized users administrative rights to the Linux system, enabling them to take full control of potential target ECUs. However, it is important to note that this vulnerability on its own DOES NOT PRESENT HIGH RISK to automakers as malicious actors still require initial code execution access to the ECU in order to exploit it. 

In the event of compromise and without specific security mechanisms in place, an exploit of this vulnerability could enable access to safety critical components. Even in secured architectures, the vulnerability may enable vehicle tracking, access to sensitive data, and Denial of Service of the target ECU. 

What Should Vehicle Manufacturers Do?   

The first thing that vehicle manufacturers should do is determine if this vulnerability affects your ECUs and if so, which ECUs. Once you understand your risk exposure, you can determine if you need to initiate a mitigation plan.

With this in mind, protecting APIs is becoming extremely important in the  IT world, and ultimately, in the automotive industry which relies on advanced technologies. To start, automotive CISOs and fleet managers need to look beyond standard risk assessments and penetration tests and add an additional layer of protection around connected car services.

Because this is most likely not the last time that a vulnerability of this nature will be exposed, preventative security mechanisms should be introduced into new ECUs.  

PlaxidityX Connected ECU Protection includes independent modules that work individually, or together, to help vehicle manufacturers prevent a wide range of exploits, including exploits like this one, from targeting connected ECUs. The solution also helps vehicle manufacturers comply with regulations and standards like UNECE UNR 155 (WP. 29).

For more information about the vulnerability, see Qualy’s blog

Ready to See Plaxidityx in Action?

“We chose PlaxidityX based on its proven experience, knowledge, methodology, and expertise..PlaxidityX’s ability to complete and submit in an extremely short time with top quality results, was critical for meeting our business goals”

Emrah Duman

“PlaxidityXs’ comprehensive suite of cyber security solutions and its outstanding array of strategic technological partnerships have contributed to the company’s leadership position”

Dorothy Amy

“The partnership with PlaxidityX enables our customers to perform cybersecurity testing on our established test platforms ..We are excited to partner with a strong and experienced cybersecurity service provider such as PlaxidityX”

Dr. Herbert Schütte

“By combining PlaxidityX’s expertise in securing connected vehicles with Microsoft’s Azure AI capabilities, we have a unique opportunity to accelerate ‘shift left’ security innovations across the entire automotive sector..”

Dominik Wee

“PlaxidityX is a key pillar of Continental’s SDV strategy, enabling Continental to implement a security-by-design approach. As automotive cyber security moves to the cloud, PlaxidityX’ cutting-edge technologies and proven VSOC capabilities position us advantageously to meet our customers’ future needs”

Gilles Mabire

Learn how we bring peace of mind for millions of drivers