Mapping the landscape of software vulnerabilities in connected vehicles
Abstract
The increased level of connectivity for vehicles leads to sophisticated and challenging software security concerns for automotive Original Equipment Manufacturers (OEMs) and suppliers. With a Connected Vehicle (CV) communicating with multiple entities (road infrastructure, other vehicles, OEMs, cloud, etc.), new attack surfaces are exposed to intruders. For instance, in 2023, ethical hackers demonstrated remote access to critical vehicle controls like steering and braking through vulnerabilities in infotainment and telematics systems. Several OEMs also reported production disruptions due to ransomware targeting software development infrastructure. Additionally, the current state of the art fails to provide a holistic view of a secure software development process for CVs. This paper presents a survey of automotive software vulnerabilities and associated attack vectors and analyzes the significant changes in security trends. Moreover, the vulnerabilities are tracked across the Software Development Life Cycle (SDLC). We include 413 new automotive software vulnerabilities identified within the last 2 years and 9 months in our study. Additionally, 20 automotive software repositories with 827 vulnerable libraries are identified by scanning sources such as repositories, SBOMs (Software Bill of Materials), images, and manifest files. We provide several security recommendations for software engineering teams based on the findings. Our findings are a step forward to support the maintenance of automotive software quality in terms of security across its entire life cycle.