Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • October 25, 2016
    US DOT issues federal guidance for improving motor vehicle cyber security
    The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
  • January 26, 2012
    Debating road user charging systems
    Are pre-launch trials of charging systems the way to improve public acceptance? Or is the real key a more robust political attitude? Here, leading system suppliers discuss the issue. The use of distance-based Road User Charging (RUC) is now well established, at least for heavy goods vehicles on strategic roads. However demand management for all vehicles, whether a distance-based charge or some form of cordon scheme, has yet to make significant progress. This is in spite of the logic and equity of RUC being
  • March 2, 2012
    Need for standardisation of toll classes
    In a previous article Bob Lees of Idris Technology Ltd looked at the appropriateness of toll classes in relation to all-electronic toll fee collection. Here, he looks at how addressing classification standardisation could avoid downstream aggravation and cost
  • September 5, 2014
    Major growth predicted for OEM embedded telematics
    According to a new research report by Berg Insight, shipments of OEM embedded telematics systems worldwide are forecasted to grow from 8.4 million units in 2013 at a compound annual growth rate (CAGR) of 30.6 per cent to reach 54.5 million units in 2020. Moreover, Berg Insight forecasts that the number of cars sold worldwide equipped with head-units featuring handset-based telematics capabilities will grow from 7 million in 2013 to 68.5 million in 2020.