Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

For more information on companies in this article

Related Content

  • A need for order in evolution
    February 27, 2012
    The hit film Jurassic Park took its name from one of the several geological periods or epochs (as they are also known) in which dinosaurs were the dominant land-dwellers.
  • Coded exchanges
    July 24, 2012
    For many, Ethernet- and IP-based networks are the cast-iron solution to ITS's communications needs. However, there remain issues from manufacturer to manufacturer with interpretation of what are supposed to be common standards The 'promise' of Ethernet was that different devices such as IP video cameras and traffic signals could be easily integrated into communications networks, simplifying the process of transporting data over copper, fibre or wirelessly. However, although Ethernet devices have come to pre
  • Monitoring, detection and control systems inside tunnels can do much to improve traveller safety
    August 6, 2013
    ITS technology can do a great deal to improve tunnel safety, as Colin Sowman discovers. It was back in April 2004 that the European Parliament adopted the EU Directive which lays down the Minimum Safety Requirements for Tunnels in the Trans-European Road Network (2004/54/EC). This was the first unitary legislation setting minimum safety standards for European road tunnels and was designed to harmonise the management of tunnel safety at a national level. Operators of existing tunnels have until 30 April 201
  • Go Denver opens up a world of seamless mobility and better data-driven decisions
    June 5, 2017
    Denver’s pioneering Go Denver mobility-as-a-service app has attracted 7,000 users in a matter of months. Geoff Hadwick heard how at ITS International’s recent conference. If Mobility-as-a-Service (MaaS) is ever going to work, it needs to have “one universal platform everywhere” according to Sean Mackin, former manager of parking and mobility services at the Denver transportation and mobility department and now Colorado branch manager for ABM Parking & Transportation. Speaking at the recent MaaS Market confe