NVD

Id
18587  
Name
CVE-2016-2354  
Description
The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without a PIN, which allows remote attackers to send arbitrary CAN commands by leveraging access to a device inside or adjacent to the vehicle, as demonstrated by a CAN command to disrupt braking or steering.  
Reject
 
CVSS Version
2  
CVSS Score
8  
Severity
High  
CVSS Base Score
8  
CVSS Impact Subscore
9.5  
CVSS Exploit Subscore
6.5  
CVSS Vector
(AV:A/AC:L/Au:N/C:P/I:C/A:C)  
Pub Date
2017-01-19  
Published
2016-04-21  
Modified Date
2016-05-31  
Seq
2016-2354  

Actions