Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

For more information on companies in this article

Related Content

  • A coalition of the willing: iATL
    April 5, 2024
    A living lab on the streets of Georgia, US, is helping to improve traffic safety by real-world deployments of technology. ITS International talks to the founder and some of the partners at the Infrastructure Automotive Technology Laboratory
  • Tolling is still stuck on the sidelines says ASECAP speaker
    August 19, 2015
    Geoff Hadwick attended ASECAP’s 2015 Study Days meeting in Lisbon and found a frustrated European tolling sector undertaking some soul searching. The international road tolling industry its failing to make it case and the sector is losing out to a range of other socio-political lobby groups according to International Bridge, Tunnel and Turnpike Association (IBTTA) chief executive Pat Jones. Speaking at the recent 2015 ASECAP Study Days conference in Lisbon, Jones issued a stark warning: “Tolling is still o
  • Loop detection still has a part in traffic management
    March 2, 2012
    Bob Lees, co-founder of Diamond Consulting Services, on why the loop detector just refuses to go away. The more strident proponents of newer and emergent detection technologies are quick to highlight what they see as the disadvantages, and hence the imminent passing, of the humble inductive loop. The more prosaic will acknowledge that loops continue to have a part to play in traffic management, falling back on the assertion that it is all a question of application. And yet year after year the loop, despite
  • Roadside monitoring used to target non-compliant trucks
    March 9, 2016
    The UK’s DVSA is utilising existing technology to identify non-compliant commercial vehicles and target repeat offenders while avoiding law-abiding companies. Enforcing the compliance of commercial vehicles (goods vehicles over 3.5 tonnes and vehicles with eight or more passenger seats) on the UK’s roads is the responsibility of the DVSA (the Driver and Vehicle Standards Agency). The Department for Transport created the executive agency about 18 months ago by merging the Driving Standards Agency (DSA) and t