Technology Sectors

Market Sectors

Highway traffic monitoring system has exploitable electronic flaw, says CERT

Systems that can track automotive traffic on roadways, providing speed and highway traffic behavior patterns, have a flaw that could allow a skilled hacker to break in, according to the U.S. Industrial Control System Computer Emergency Readiness Team. (ICS-CERT)

A Nov. 30 advisory issued by CERT said a specific system used by some municipal governments around the country has an authentication vulnerability that could allow unauthorized access. The advisory said Post Oak Bluetooth traffic systems that use Anonymous Wireless Address Matching (AWAM) were affected.

AWAM systems detect vehicles that have Bluetooth-enabled networking devices aboard, including cellular phones, mobile GPS systems, telephone headsets, and in-vehicle navigation and hands-free systems. Each of those devices contains a unique electronic address that the AWAM system’s sensors can read as the device travels by on a roadway. The addresses aren’t tied to the users, so the tracking information can be used to track people, however.  

The AWAM systems are used as an alternative by some municipal governments and transportation departments to EZ-Pass RFID tags to watch for traffic jams and other traffic disruptions by measuring highway speeds and travel times.

An independent research group, said CERT on Nov. 30, identified an insufficient entropy vulnerability in authentication key generation in Post Oak’s AWAM Bluetooth Reader Traffic System. By impersonating the device, said CERT, an attacker could obtain the credentials of the systems administrative users and potentially perform a Man-in-the-Middle (MitM) attack, intercepting communications within the organization.

CERT said Post Oak has validated the vulnerability and produced an updated firmware version that mitigates the potential opening. CERT said Post Oak told it its products are deployed in the transportation sector, mainly in the U.S.

 

Upcoming Events

Event Details Dates of Event
Critical Security Controls International Summit 2013 Apr 26 - May 2
Secure India @Bangalore 2013 Apr 29 - May 4
Cloud Security Alliance CCSK Certification Training May 6 - 7
SANS Security West 2013 May 9 - 19
SANS Brisbane 2013 May 13 - 18
GovSec Conference & Expo May 14 - 15
CPM East Conference & Expo May 14 - 15
TREXPO - The Law Enforcement Expo May 14 - 15
SANS Austin 2013 May 19 - 24
DoD VA Healthcare Training Forum May 20 - 23
ISSA-LA Fifth Annual Information Security Summit May 21 - 21
Southwest Microwave Seminar May 21 - 21
Southwest Microwave Seminar May 21 - 21
Southwest Microwave Perimeter Defense Seminar May 21 - 21
Southwest Microwave Seminar May 22 - 22
Transport and Logistics of Hazardous Material May 27 - 28
Southwest Microwave Seminar May 28 - 28
Border Management Southwest Summit May 29 - 31
Cyber Security Conference & Expo May 30 - 30
Mobile Device Security Summit 2013 May 30 - Jun 6
Security Analytics Summit 2013 May 30 - Jun 6
Cyber Security Conference & Expo May 30 - 30
Southwest Microwave Seminar May 30 - 30
SANS Malaysia @ MCMC 2013 Jun 3 - 8
2013 SIA Government Summit Jun 4 - 5
Southwest Microwave Seminar Jun 4 - 4
NCT: CBRNe Israel, 4 - 6 June 2013, Tel Aviv Jun 4 - 6
SEL Modern Solutions Power Systems Conference Jun 5 - 7
Mission Command Jun 10 - 12
Cyber Securty Brainstorm Jun 11 - 11
EDGE Summit 2013 Jun 11 - 11
IPv6 Summit 2013 Jun 14 - 16
SANSFIRE 2013 Jun 15 - 22
Oak Ridge National Laboratory's 2nd Biosurveillance Symposium Jun 17
Biodetection Technologies 2013 Jun 18 - 19
Southwest Microwave Seminar Jun 18 - 18