CVE-2022-36945

Published Aug 24, 2022

Last updated a year ago

CVSS medium 6.4
Keyless entry

Overview

Description
The Remote Keyless Entry (RKE) receiving unit on certain Mazda vehicles through 2020 allows remote attackers to perform unlock operations and force a resynchronization after capturing three consecutive valid key-fob signals over the radio, aka a RollBack attack. The attacker retains the ability to unlock indefinitely.
Source
cve@mitre.org
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
6.4
Impact score
5.2
Exploitability score
1.2
Vector string
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Severity
MEDIUM

Weaknesses

nvd@nist.gov
CWE-294

Social media

Hype score
Not currently trending

Configurations