Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • January 19, 2012
    ITS industry needs more effort to get to the future
    Eric Sampson, visiting professor at Newcastle University and City University London and ambassador for ITS-UK, provides a retrospective on the last couple of decades and takes a look at what the ITS industry still needs to do to get to where it needs to be
  • September 13, 2016
    Karamba’s Carwall thwarts mass hacks
    Karamba Security’s Carwall software is said to prevent ‘mass hacks’ of vehicles’ on-board systems including those for connected and autonomous driving. Carwall sits in the vehicle ECUs and ‘learns’ the factory settings. If hackers breach the manufacturer’s cyber security and tries to infect the ECUs of in-service vehicles, Karamba’s software detects the impending change to factory settings and blocks activation. David Barzilai, the company’s chairman and co-founder, said with tens of millions of l
  • November 10, 2017
    Making connections without compromising security
    We listen in as global experts discuss connected vehicles and cybersecurity. By 2019 there will be almost 44 million connected cars globally and by 2022 that figure will be nearer 70 million; some 40% will be electric powered, according to market analyst Frost & Sullivan. But its report said the issue of end-to-end security for the new technology is still under debate, as vehicle OEMs engage with vendors to test specific security application areas for both over-the-air and vehicle-to-exterior services.
  • July 30, 2013
    Tollers make way as NextNav muscles into 902-928MHz spectrum
    Toll operators and Progeny trade claim and counter claim about the potential ramifications of operating in the 902-928MHz spectrum, as Jon Masters finds out. Two months after the Federal Communications Commission (FCC) determined that Progeny can start commercial operation of its NextNav location finding service, the dust has begun to settle. The tolling industry has had a chance to reflect on how this may impact its operations, in the knowledge that NextNav will share the 902-928MHz frequency band with RFI