Full Report
Aftermarket dealer-installed KARR/SWDS security systems all use the same secure key, say UCSD researchers
Analysis Summary
# Vulnerability: Hardcoded Bluetooth Encryption Key in KARR/SWDS Security Systems
## CVE Details
- **CVE ID:** CVE-2024-41132
- **CVSS Score:** 7.1 (High)
- **CWE:** CWE-321 (Use of Hard-coded Cryptographic Key)
## Affected Systems
- **Products:** Aftermarket dealer-installed security systems manufactured by Acrisure (SWDS/KARR).
- **Versions:** Systems equipped with specific Bluetooth-related components manufactured within the last nine years.
- **Configurations:** Vehicles from dealerships including Honda, Toyota, Mazda, Ford, and Jeep. Notably, the hardware remains active and vulnerable even if the vehicle owner did not purchase or activate the subscription service.
## Vulnerability Description
Researchers at UC San Diego discovered that at least 2.2 million KARR and SWDS security devices utilize a universal, hardcoded "secure key" for Bluetooth communication. Because the devices share an identical cryptographic key rather than unique per-device credentials, an attacker who possesses the key can authenticate to any affected system within Bluetooth range.
## Exploitation
- **Status:** PoC demonstrated by researchers; full technical details scheduled for release at DEF CON/USENIX Security (August 2024).
- **Complexity:** Low (once the universal key is known).
- **Attack Vector:** Adjacent (Bluetooth range, approximately 5 yards).
## Impact
- **Confidentiality:** Low (Access to device status).
- **Integrity:** High (Attacker can issue commands to unlock doors, flash lights, or trigger the horn).
- **Availability:** High (Attacker can trigger the starter-disable feature to prevent the vehicle from starting).
## Remediation
### Patches
- **Firmware Update:** KARR Security has released a firmware update to address the hardcoded key issue. Active and inactive users can update their systems via the official KARR mobile application.
### Workarounds
- **Hardware Removal:** Physical removal of the device from the vehicle's dashboard. Note that researchers caution this is a complex process involving the vehicle's ignition wiring and may require professional assistance.
## Detection
- **Indicators of Compromise:** Unexplained door unlocking, horn activation, or "no-start" conditions while in public areas.
- **Detection Methods and Tools:** Mobile device scans may identify KARR/SWDS Bluetooth fingerprints; however, specific identification of the vulnerability status requires checking through the official vendor app.
## References
- **Vendor Instructions:** hxxps[://]www[.]karrsecurity[.]com/karr-security-firmware-update-instructions
- **Research Announcement:** hxxps[://]today[.]ucsd[.]edu/story/2-million-cars-with-anti-theft-systems-installed-by-dealers-are-at-higher-risk-of-theft
- **Full Research Paper (Pending):** hxxps[://]par[.]nsf[.]gov/biblio/10696650