None
EN
Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More
['Sql Injection', 'Regex Authorization Bypass On Spireon Systems Allows Attacker To Access', 'Track', 'Send Arbitrary Commands To Million Telematics Systems', 'Additionally Fully Takeover Fleet Management Systems For Police Departments', 'Ambulance Services', 'Truckers', 'Many Business Fleet Systems']
Blog | Sam Curry
Ferrari Full zero-interaction account takeover for any Ferrari customer account IDOR to access all Ferrari customer records Lack of access control allowing an attacker to create, modify, delete employee "back office" administrator user accounts and all user accounts with capabilities to modify Ferrari owned web pages through the CMS system Ability to add HTTP routes on api.ferrari.com (rest-connectors) and view all existing rest-connectors and secrets associated with them (authorization headers) Ability to access and manage all data across all of Spireon Ability to fully takeover any fleet (this would've allowed us to track & shut off starters for police, ambulances, and law enforcement vehicles for a number of different large cities and dispatch commands to those vehicles, e.g.