A security flaw in the software platform , which is equipped with 2.2 million BMW worldwide, could allow an attacker to unlock the car doors from a smartphone.
The affected cars are those with Connected Drive, manufactured from March 2010 to December 8, 2014. These include BMW models (1 to 7 series, I3, X1), Mini (three-door and five-door hatchback), and Rolls Royce (Phantom Coupe and Drophead Coupe, Ghost and Wraith).
According to the German Automobile Club, ADAC, which discovered the vulnerability, car doors can be unlocked within minutes, without any sign of a break-in.
The problem appears to be caused by a lack of data encryption between Connected Drive and the company's servers, which communicate via a cellular modem with a SIM card.
The researchers noticed that the data exchange between the car and BMW's servers was not encrypted, and so they could have broken into the system and modified it. This could have been done via a base transceiver station (BTS), which can receive information from GSM devices.
ADAC discovered the vulnerability by accident and reported the findings to the manufacturer, awaiting an update before publishing the reported information. From the clarifications provided by ADAC, it is unclear whether the security flaw could also be exploited to gain access to car-related functions.
BMW says the flaw has been fixed since January 31 and has already sent out a patch to affected cars. Communication with vehicles that received the update should now be carried out in a secure manner as the data is now encrypted.

