CVE Feed

    Dashboard / CVE / CVE-2022-37418

    CVE-2022-37418

    The Remote Keyless Entry (RKE) receiving unit on certain Nissan, Kia, and Hyundai vehicles through 2017 allows remote attackers to perform unlock operations and force a resynchronization after capturing two consecutive valid key fob signals over the radio, aka a RollBack attack. The attacker retains the ability to unlock indefinitely.

    Published:Aug 24, 2022
    Last Modified:Apr 6, 2026
    EPS:Aug 24, 2022
    EPSS Score:0.01957
    CVSS Score:6.4

    Affected Products

    Vendor
    Hyundai
    Product
    Hyundai
    Vendor
    Hyundai
    Product
    Hyundai Firmware
    Vendor
    Kia
    Product
    Kia
    Vendor
    Kia
    Product
    Kia Firmware
    Vendor
    Nissan
    Product
    Nissan
    Vendor
    Nissan
    Product
    Nissan Firmware

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High