宝马汽车实验安全性评估总结报告(英文版)_26页_2mb
报告摘要
Summary Report: Experimental Security Assessment of BMW Cars
Core Content
This report presents the findings of a security assessment conducted on modern BMW vehicles, focusing on their Infotainment System (Head Unit), Telematics Control Unit (TCB), and Central Gateway Module. The research aimed to evaluate the security risks associated with these components and their communication interfaces.
Main Components and Their Vulnerabilities
1. Infotainment System (Head Unit)
The Head Unit, also known as NBT or HU_ENTRYNAV, is composed of two subsystems:
- hu-intel: A QNX system running on an Intel x86 chip, responsible for multimedia and ConnectedDrive services.
- hu-jacinto: A QNX system on a Jacinto ARM chip, managing power and CAN-bus communication.
Key Vulnerabilities:
- USB Interface:
- Vulnerable to local code execution via malformed update content.
- No security restrictions allow port scanning and internal service detection.
- E-NET over OBD-II:
- Allows bypassing code signing via SMS to trigger remote functions.
- Enables root access to the hu-intel system.
- Bluetooth Stack:
- Memory corruption vulnerability can be exploited to crash the Bluetooth service.
- Leads to system reboot via internal watchdog.
- ConnectedDrive Service:
- Insecure implementation allows interception and exploitation of traffic.
- Enables remote code execution and privilege escalation.
- K-CAN Bus:
- Allows sending arbitrary CAN messages via two methods:
- Reusing CAN-bus driver code from TI.
- Hooking CAN-bus driver functions.
- Allows sending arbitrary CAN messages via two methods:
2. Telematics Control Unit (TCB)
Produced by "Peiker Acoustic GmbH", the TCB provides remote services and emergency call functions via cellular networks.
Key Vulnerabilities:
- NGTP (Next Generation Telematics Patterns):
- Allows sending arbitrary NGTP messages via SMS to trigger remote services.
- No encryption or signature checks, making it vulnerable to spoofing.
- Remote Diagnosis:
- "LastStateCall" task can be exploited to send UDS messages to ECUs.
- Enables remote code execution and root access.
3. Central Gateway Module
This module acts as a bridge between different CAN buses and other communication protocols. It has two main versions: ZGW (older) and BDC (newer).
Key Vulnerabilities:
- Cross-Domain Diagnostic Messages:
- Allows sending UDS messages to various ECUs across different domains.
- Weakens secure isolation between vehicle systems.
- Lack of High Speed Limit on UDS:
- ECUs respond to diagnostic messages even at normal driving speeds.
- Enables potential for remote control and manipulation of vehicle functions.
Attack Chains
Two types of attack chains were identified:
1. Contacted Attack
- Exploits physical access through USB or OBD-II interfaces.
- Allows installation of backdoors and manipulation of the vehicle via the Central Gateway Module.
2. Contactless Attack
- Utilizes wireless communication channels:
- Bluetooth: Can be exploited to crash the Head Unit and cause reboot.
- Cellular Network: Requires setting up a rogue base station and using MITM techniques.
- Attackers can exploit vulnerabilities in NBT and TCB to inject malicious CAN messages.
Vulnerable BMW Models
The following models were tested and found to be affected:
| Model | Manufacture Date | Central Gateway | Head Unit | Telematics Control Unit |
|---|---|---|---|---|
| BMW i3 94(+REX) | 2017.02.15 | BDC (I01) | HU_NBT (MN-003.013.001 TN-003.013.001) | TCB NAD (003.017.020 APPL) |
| BMW X1 sDrive 18Li | 2016.07.27 | BDC (F49) | HU_ENTRYNAV (MV-130.006.007 TV-130.006.007) | TCB NAD (003.017.020 APPL) |
| BMW 525Li | 2016.04.27 | FEM (F18) | HU_NBT (MN-003.003.001 TN-003.003.001) | TCB NAD (003.015.022 APPL) |
| BMW 730Li | 2012-10-08 | ZGW (F02) | HU_NBT (MN-001.020.022 TN-001.020.022) | TCB NAD (001.014.022 APPL) |
Note: The scope of vulnerable models is difficult to precisely confirm due to varying firmware versions and component configurations across models.
Disclosure Process
- January 2017: Keen Lab initiated internal research on BMW security.
- February 2018: All findings were validated in a controlled environment.
- February 25, 2018: Keen Lab reported findings to BMW.
- March 9, 2018: BMW confirmed all reported vulnerabilities.
- March 22, 2018: BMW shared mitigation plans.
- April 5, 2018: CVE numbers were reserved.
- May 22, 2018: Summary report was released publicly.
- 2019: Full technical report will be published.
Key Findings
- Multiple vulnerabilities exist in the Head Unit, TCB, and Central Gateway Module.
- These vulnerabilities can be exploited via USB, OBD-II, Bluetooth, and cellular networks.
- Attackers can remotely gain control of the CAN buses and manipulate vehicle functions.
- BMW has started implementing mitigation measures, including firmware updates and configuration changes.
Conclusion
The research has demonstrated that modern BMW vehicles are vulnerable to both local and remote attacks through various interfaces. The vulnerabilities allow for the execution of arbitrary diagnostic requests and remote control of the vehicle's internal systems. While the full technical details will be published in 2019, the summary report aims to raise awareness and encourage timely security updates from BMW.
试读结束,高清完整版pdf/doc/ppt,请点下载