Password Reset Hack Exposed in Honda’s E-Commerce Platform, Dealers Data at Risk

June 12, 2023Ravi LakshmananData safety/hacking

password reset hack

A security vulnerability discovered in Honda’s e-commerce platform could have been exploited to gain unrestricted access to sensitive dealer information.

“Broken or missing access controls allowed access to all data on the platform even when logged in as a test account,” security researcher Eaton Zveer said in a report released last week. said in

The platform is designed for the sale of power equipment, marine, lawn and gardening businesses. The automobile sector of Japanese companies will not be affected.

In a nutshell, this hack abused the password reset mechanism of one of Honda’s sites, Power Equipment Tech Express (PETE), to reset the password associated with the account and gain full admin-level access. to get

cyber security

This is possible because the API allows any user to send a password reset request without entering the password associated with their account, just by knowing their username or email address.

With this feature, a malicious attacker could sign in and take over another account, then take advantage of the sequential nature of the dealer site URL (i.e. “admin.pedealer.honda”).[.]com/dealersite//dashboard) to gain unauthorized access to another dealer’s admin dashboard.

Honda e-commerce

“Just increment that ID and you’ll have access to all dealers’ data,” Zveare explained. “Underlying JavaScript code takes that ID and uses it in API calls to retrieve data and display it on the page. I did.”

Worse, this design flaw can be used to gain access to the dealer’s customers and edit their websites and products, or even worse, to compromise the entire platform using specially crafted tools. You could have elevated your privileges to administrator or something. This is a feature exclusive to Honda employees. Request to view details of our dealer network.

upcoming webinars

🔐 Mastering API Security: Understanding Your True Attack Surface

Discover untapped vulnerabilities in your API ecosystem and take proactive steps towards ironclad security. Join us for an insightful webinar!

join the session

In total, this vulnerability exposed 21,393 customer orders across all dealers, 1,570 dealer websites (1,091 of which were active), 3,588 dealer accounts, and 1,090 dealer accounts from August 2016 to March 2023. Unauthorized access to emails and 11,034 customer emails was granted.

Threat actors can also take advantage of access to these dealer websites for illegal profit by embedding skimmers and cryptocurrency mining code.

This vulnerability was addressed by Honda on April 3, 2023 following a responsible disclosure on March 16, 2023.

The disclosure details Zubea detailing security issues with Toyota’s Global Supplier Readiness Information Management System (GSPIMS) and C360 CRM, which may have been exploited to gain access to rich corporate and customer data. This was done several months after the disclosure of

Did you enjoy this article? Follow us twitter You can read more exclusive content we post on LinkedIn.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *