Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • August 17, 2022
    ITS investment on upward curve
    More money is coming into the ITS sector – but where is it likely to go next? And what are the pros and cons of all this cash? Adam Hill talks to ITS veteran and corporate investment adviser Greg McKhann
  • May 3, 2013
    ITS America: building the infrastructure for V2X
    By 2024, market penetration of factory fit DSRC-equipped vehicles in the US could rise to 30 per cent, according to US Department of Transportation AASHTO Deployment Analysis 2012, enabling widespread data communications services and kick-starting a national DSRC infrastructure. The question is: who will pay for the infrastructure in the first place? In an interview with Steve Bayless, director of telecomms and telematics at ITS America, Telematics Update investigated which key investors will benefit from s
  • February 2, 2012
    What's next for transport communication systems?
    Moxa Americas, Inc.'s Charles Chen ponders the way forward for transportation communications networks in the US
  • July 31, 2012
    Debating the future development of ANPR
    What future is there for automatic number plate recognition? Will it be supplanted by electronic vehicle identification, or will continuing development maintain the technology's relevance? In recent years, digitisation and IP-based communication networks have allowed Automatic Number Plate Recognition (ANPR) to achieve ever-greater utility and a commensurate increase in deployments. But where does the technology go next - indeed, does it have a future in the face of the increasing use of, for instance, Dedi