Hijacking a Fleet of Agricultural Vehicles
Challenge
The client developed a physical device and API designed to deliver files to large agricultural vehicles’ onboard computers and to read engine statistics from the vehicle’s Controller Area Network (CAN) bus. However, the platform was found to be vulnerable to two separate privilege escalation issues, as customers were provided with at least one limited administrator account.
Solution
ivision uncovered a vulnerability that allowed an attacker to escalate privileges to Super Admin and upload malware, which could then be replicated across all devices in the field. With this level of access, the attacker-controlled malware would gain unrestricted read and write capabilities on the vehicle’s CAN bus.