CVE-2023-3028

Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of vehicles using the HopeChart HQT-401 telematics unit. Other models are possibly affected too. Multiple vulnerabilities were identified: - The MQTT backend does not require authentication, allowing unauthorized connections from an attacker. - The vehicles publish their telemetry data (e.g. GPS Location, speed, odometer, fuel, etc) as messages in public topics. The backend also sends commands to the vehicles as MQTT posts in public topics. As a result, an attacker can access the confidential data of the entire fleet that is managed by the backend. - The MQTT messages sent by the vehicles or the backend are not encrypted or authenticated. An attacker can create and post messages to impersonate a vehicle or the backend. The attacker could then, for example, send incorrect information to the backend about the vehicle's location. - The backend can inject data into a vehicle´s CAN bus by sending a specific MQTT message on a public topic. Because these messages are not authenticated or encrypted, an attacker could impersonate the backend, create a fake message and inject CAN data in any vehicle managed by the backend. The confirmed version is 201808021036, however further versions have been also identified as potentially impacted.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hopechart:hqt401_firmware:201808021036:*:*:*:*:*:*:*
cpe:2.3:h:hopechart:hqt401:-:*:*:*:*:*:*:*

History

28 Sep 2023, 06:15

Type Values Removed Values Added
References
  • {'url': 'https://garage.asrg.io/cve-2023-3028-improper-backend-communications-allow-access-and-manipulation-of-the-telemetry-data/', 'name': 'https://garage.asrg.io/cve-2023-3028-improper-backend-communications-allow-access-and-manipulation-of-the-telemetry-data/', 'tags': ['Permissions Required'], 'refsource': 'MISC'}
  • (MISC) https://asrg.io/security-advisories/cve-2023-3028/ -

25 Sep 2023, 02:29

Type Values Removed Values Added
CPE cpe:2.3:a:mqtt:mqtt:201808021036:*:*:*:*:*:*:* cpe:2.3:o:hopechart:hqt401_firmware:201808021036:*:*:*:*:*:*:*
cpe:2.3:h:hopechart:hqt401:-:*:*:*:*:*:*:*
First Time Hopechart
Hopechart hqt401 Firmware
Hopechart hqt401

09 Jun 2023, 17:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:mqtt:mqtt:201808021036:*:*:*:*:*:*:*
First Time Mqtt mqtt
Mqtt
CWE CWE-287
References (MISC) https://garage.asrg.io/cve-2023-3028-improper-backend-communications-allow-access-and-manipulation-of-the-telemetry-data/ - (MISC) https://garage.asrg.io/cve-2023-3028-improper-backend-communications-allow-access-and-manipulation-of-the-telemetry-data/ - Permissions Required

01 Jun 2023, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-01 06:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-3028

Mitre link : CVE-2023-3028

CVE.ORG link : CVE-2023-3028


JSON object : View

Products Affected

hopechart

  • hqt401
  • hqt401_firmware
CWE
CWE-287

Improper Authentication

CWE-319

Cleartext Transmission of Sensitive Information

CWE-345

Insufficient Verification of Data Authenticity