CVE-2017-6052 describes a Man-in-the-Middle (MitM) vulnerability in Hyundai Motor America Blue Link versions 3.9.5 and 3.9.4, stemming from unverified communication channel endpoints. This flaw could allow an attacker on an adjacent network to intercept or influence communications between the application and its services. Rated with a CVSS score of 3.7 (LOW), exploitation requires high attack complexity and would result in low impact to confidentiality and integrity. There is no evidence of active exploitation, no public exploit code, and it is not listed on CISA's Known Exploited Vulnerabilities catalog. Community discussion and exploit intelligence for this specific CVE are minimal, despite one media article mentioning broader Hyundai app vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.9.4CPE matchmatch criteria | cpe:2.3:a:hyundai:blue_link:3.9.4:*:*:*:*:*:*:* | ||
3.9.5CPE matchmatch criteria | cpe:2.3:a:hyundai:blue_link:3.9.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.2 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.