HomeSecurityPwn2Own Automotive 2024: Researchers "hacked" Tesla

Pwn2Own Automotive 2024: Researchers “hacked” Tesla

Security researchers were able to hack Tesla and won $722,500 in rewards on the first day of Pwn2Own Automotive 2024 (for finding three bug collisions and 24 unique zero-day exploits).

Pwn2Own Automotive 2024

Specifically, the Synacktiv (@Synacktiv) won $100,000 after showing how someone can gain root access to a Tesla Modemby patching three zero-day vulnerabilities.

Additionally, the researchers used other combinations of two bugs to hack a Ubiquiti Connect EV Station and a JuiceBox 40 Smart EV Charging Station. Thanks to this discovery, they earned an additional $120,000.

A third exploit chain targeted the ChargePoint Home Flex EV charger. This attack was already known, but it earned researchers $16,000, giving them a total of $295,000 during the first day of the Pwn2Own Automotive 2024 competition.

See also: Tesla Model Y: The most popular vehicle in Europe for 2023

Other researchers have managed to hack into updated EV charging stations and infotainment systems. NCC Group EDG won $70,000 for discovering and exploiting zero-day vulnerabilities in the Pioneer DMH-WT7600NEX infotainment system and the Phoenix Contact CHARX SEC-3100 EV charger.

After exploiting and reporting zero-day bugs during the Pwn2Own contest, compromised companies have 90 days to release security. After that period, TrendMicro's Zero Day Initiative publicly discloses the vulnerabilities, putting vulnerable systems at greater risk.

The Pwn2Own Automotive 2024 hacking competition focuses on technologies and takes place this week in Tokyo.

Throughout the competition, security researchers will be able to target Tesla's In-vehicle Infotainment (IVI) systems, electric vehicle (EV) chargers, and car operating systems.

Researchers will also present zero-day exploits targeting Tesla Model 3/Y (Ryzen-based) or Tesla Model S/X (Ryzen-based) systems, including the infotainment system, modem, tuner, wireless network, and autopilot.

See also: Tesla: Another adjustment to salary increases

Pwn2Own Tesla hacked

The competition's top prize will be awarded for VCSEC, gateway or autopilot zero-days, with a cash prize of $200,000 and a Tesla car.

Pwn2Own Automotive is a competition that promotes innovation and security in the automotive industry. One of the main advantages is that it stimulates research and development in the field of security, as participants try to identify and exploit vulnerabilities before malicious users do.

Additionally, Pwn2Own Automotive helps raise public awareness of the security issues facing modern cars, allowing car manufacturers to be aware of potential threats and patch vulnerabilities in a timely manner.

See also: Tesla Cybertruck: 160-mile range in first towing test

However, the competition can create an illusion of security. Manufacturers may feel that cars are safe because they have been tested in Pwn2Own, but real-world attacks can be very different from the testing conditions. Therefore, manufacturers should be constantly vigilant and monitor their vehicle systems.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS