There are two vulnerabilities in BMW's ConnectedDrive Web portal that could allow an intruder to interfere with the car's settings related to its infotainment system.
ConnectedDrive is the name of BMW's in- car infotainment system. The system can be used as is, in the car, or via a series of connected mobile apps that allow the driver to manage vehicle settings via their mobile devices. In addition to the mobile apps , this service also exists on the Web.
Benjamin Kunz Mejri, a security researcher for Vulnerability Lab, yesterday published two zero-day vulnerabilities in the ConnectedDrive portal that BMW had failed to patch for the past five months.
Topic #1: VIN session hijacking
The first issue is a session vulnerability that allows a user to gain access to the VIN (Vehicle Identification Number) of another user.
VINs are identifiers for the cars associated with each user's account. A VIN code is used to back up the car's ConnectedDrive settings to the corresponding account. Changing these settings in the Web portal will change them in the car and in the attached apps.
Mejri says that the attack allowed him to bypass the VIN session validation process and use another VIN to gain access and, subsequently, edit the car settings of another user.
Some of the settings available through the ConnectedDrive portal include the ability to lock/unlock the vehicle, manage music playlists, access email accounts, manage routes, real-time traffic information and others.
Topic #2: XSS in the ConnectedDrive portal
The second issue is an XSS (cross-site scripting) bug on the portal's password reset page.
This XSS bug can lead to regular complications arising from such Web attacks, such as browser cookie harvesting, subsequent CSRF attacks, phishing attacks , and many more.
Mejri claims to have notified BMW of these two issues in February 2016. Since BMW failed to respond to Mejri's bug reports in a timely manner, the researcher has made his findings public. An in-depth description of the issues and the full proof of concept exploit code can be found here (first issue) and here (second issue).
Almost a year ago, security researcher Samy Kamkar revealed that his OwnStar car hacking toolkit also worked with BMW's remote service.

