Details of the hack and disclosure set out nicely in this paper.
https://www.computest.nl/wp-content/...ar-rapport.pdf
Looks like this vulnerability effects all VAG MIB equipped cars built before week 22 of 2017.
(The VAG letter says week 22 of 2016, but given the timeline of research and disclosure, must be 2017.)
Current : 2017 Mk7 Golf R (most options) || 2012 Golf Mk6 TDi (few options)
Gone : 2004 Bora V6 4Motion (few klms, all options)
><(((°> ><(((°>
Thanks for sharing.
In summary:
If your car has a SIM internet connection it is likely vulnerable to an exploit which the attacker can use to gain some limited access.
Recommendation is to remove the SIM.
This same exploit can be had via WiFi or a connected phone via USB.
Only connect your car to a trusted network. The phone SIM network is not trusted.
Only connect a trusted device to your car.
Arteon & T-Roc
Bookmarks