CVE-2021-46145 describes a replay attack vulnerability in the keyfob subsystem of Honda Civic 2012 vehicles, stemming from a non-expiring rolling code and counter resynchronization issue. This medium-severity vulnerability (CVSS 5.3) allows an attacker in close proximity to unlock the vehicle, with a high impact on integrity. While there is no known exploit code in Metasploit or Nuclei, the vulnerability has garnered significant community attention and media coverage, including reports of its potential to unlock and start vehicles remotely. Despite this, it is not listed on the CISA KEV catalog and is currently inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:honda:civic_2012:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.