← Back to home
ICSA-17-234-04  ·  Published 2018-01-09  ·  View on CISA ICS-CERT ↗

General Motors and Shanghai OnStar (SOS) iOS Client

CVSS 9.8 CRITICAL

Risk Summary

ATTENTION: Remotely exploitable/low skill level to exploit.

Remediations

  • Users should not root or jailbreak their phones to prevent the preconditions for attacker access to mobile phone memory, including the ability to read JSON web token encryption keys.
  • GM HTTP Public Key Pinning rollout is complete to mitigate Man-In-The-Middle attacks for SOS iOS Client Version 7.1. The rollout includes back office and iOS client changes (now version 7.2). For North America iOS OnStar clients, HTTP Public KeyPinning deployment (back office and mobile app) is scheduled for December 2017.
  • Debugging code was removed from SOS Identity Management servers to prevent attacker access to user accounts.

Affected Vendors

General Motors (GM), Shanghai OnStar (SOS)

Affected Products (1)

General Motors (GM), Shanghai OnStar (SOS) · Shanghai OnStar iOS Client 7.1

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more