{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2025-6030",
        "assignerOrgId": "c15abc07-96a9-4d11-a503-5d621bfe42ba",
        "state": "PUBLISHED",
        "assignerShortName": "ASRG",
        "dateReserved": "2025-06-12T14:11:08.030Z",
        "datePublished": "2025-06-13T14:38:58.103Z",
        "dateUpdated": "2025-06-13T14:51:37.000Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "Cyclone Matrix TRF",
                    "vendor": "Autoeastern",
                    "versions": [
                        {
                            "changes": [
                                {
                                    "at": "L-ALARMATRF-001",
                                    "status": "unaffected"
                                }
                            ],
                            "lessThanOrEqual": "2025",
                            "status": "affected",
                            "version": "2024",
                            "versionType": "date"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Danilo Erazo"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the&nbsp;Key Fob Transmitter in Cyclone Matrix TRF&nbsp;Smart  Keyless Entry System, which allows a replay attack.<br><br>Research was completed on the 2024 KIA Soluto.&nbsp; Attack confirmed on other KIA Models in Ecuador.&nbsp;"
                        }
                    ],
                    "value": "Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart  Keyless Entry System, which allows a replay attack.\n\nResearch was completed on the 2024 KIA Soluto.  Attack confirmed on other KIA Models in Ecuador."
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-115",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-115 Authentication Bypass"
                        }
                    ]
                },
                {
                    "capecId": "CAPEC-112",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-112 Brute Force"
                        }
                    ]
                },
                {
                    "capecId": "CAPEC-117",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-117 Interception"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "Automatable": "NO",
                        "Recovery": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "attackVector": "ADJACENT",
                        "baseScore": 9.4,
                        "baseSeverity": "CRITICAL",
                        "privilegesRequired": "NONE",
                        "providerUrgency": "NOT_DEFINED",
                        "subAvailabilityImpact": "HIGH",
                        "subConfidentialityImpact": "HIGH",
                        "subIntegrityImpact": "HIGH",
                        "userInteraction": "NONE",
                        "valueDensity": "NOT_DEFINED",
                        "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:N",
                        "version": "4.0",
                        "vulnAvailabilityImpact": "HIGH",
                        "vulnConfidentialityImpact": "HIGH",
                        "vulnIntegrityImpact": "HIGH",
                        "vulnerabilityResponseEffort": "NOT_DEFINED"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-307",
                            "description": "CWE-307 Improper Restriction of Excessive Authentication Attempts",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-294",
                            "description": "CWE-294 Authentication Bypass by Capture-replay",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "c15abc07-96a9-4d11-a503-5d621bfe42ba",
                "shortName": "ASRG",
                "dateUpdated": "2025-06-13T14:38:58.103Z"
            },
            "references": [
                {
                    "tags": [
                        "related"
                    ],
                    "url": "https://revers3everything.com/unlocking-thousands-of-cars-by-exploiting-learning-codes-from-key-fobs/"
                },
                {
                    "tags": [
                        "third-party-advisory"
                    ],
                    "url": "https://asrg.io/security-advisories/cve-2025-6030-autoeastern-smart-keyless-entry-system-replay-attack/"
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<ul><li>Replace the current Keyless Entry System (KES) with one that utilizes rolling code technology (L-ALARMATRF-001)</li><li>Avoid using key fobs with fixed or learning code systems.</li></ul>"
                        }
                    ],
                    "value": "*  Replace the current Keyless Entry System (KES) with one that utilizes rolling code technology (L-ALARMATRF-001)\n  *  Avoid using key fobs with fixed or learning code systems."
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            },
            "title": "Autoeastern Smart Keyless Entry System Replay Attack",
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-06-13T14:51:32.465517Z",
                                "id": "CVE-2025-6030",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-06-13T14:51:37.000Z"
                }
            }
        ]
    }
}