Sponsored

Rivian Constantly sending Buffer Overflow traffic to AWS

PurseChicken

Member
Joined
Sep 4, 2023
Threads
1
Messages
15
Reaction score
9
Location
Oregon
Vehicles
2024 R1S
Hello,

I was looking at my local network today, and I noticed that a device on my network is constantly being denied due to an IPS rule. Specifically in the Buffer Overflow Category with the name "SSL OpenSSL CRL Verification X.400 Address Handling Type Confusion Vulnerability (CVE-2023-0286)" Here is a link to the details of this detection in my WatchGuard appliance: https://securityportal.watchguard.com/threats/detail?ruleId=1231758

After some digging, I found that this appears to be my R1S with a MAC address that is associated with Vendor "u-blox ag" (OUI 20:BA:36). All of the traffic appears to be going to destination IP addresses that are associated with AWS. Additionally, it appears DNS lookups occur for "v1authz.prod.rivianservices.com" in the same cycle of the events.

Granted, my home setup also doubles as my lab, so I am sure I am unique in seeing this as most home users may not notice. That being said, I am posting here to see if anyone else has happened to see this on their network or if they have any insight. Definitely a discussion topic. I will likely also contact Rivian about this as well.

Thanks!
Sponsored

 

Glembi2

Well-Known Member
First Name
Chris
Joined
Dec 3, 2023
Threads
1
Messages
736
Reaction score
818
Location
Vienna, Virginia
Vehicles
R1S, Genesis GV70, Civic
Occupation
Patent attorney
Clubs
 
You may have found the cause of the increase in drain since the last update! A number of folks have noticed an increase in truck activity when it should be sleeping. Constantly pinging AWS would do it
 

tate16t

Well-Known Member
First Name
Robert
Joined
Apr 7, 2022
Threads
65
Messages
1,418
Reaction score
1,189
Location
NY
Vehicles
2023 El Cap Granite R1S
Occupation
Car Enthusiast
Can you check your logs to determine when this started? Does it coincide with the update release?
 

COdogman

Well-Known Member
First Name
Brian
Joined
Jan 21, 2022
Threads
33
Messages
11,641
Reaction score
34,494
Location
CO
Vehicles
2023 R1T
Occupation
Cyber defender
Clubs
 
Your S has become sentient and is taking its first steps. It’s Skynet all over again….
 

NY_Rob

Well-Known Member
First Name
Rob
Joined
Feb 9, 2022
Threads
23
Messages
5,417
Reaction score
7,997
Location
long island
Vehicles
Model 3 LR AWD, BMW i3 REX, 2024 Rubicon 4xe
Occupation
IT
I wonder if our vehicles will continue sending all that data if we make it "forget" our home networks or will it just find another route and send it via LTE?

That's precisely why I'm very interested in what will happen connectivity wise if we don't pay the $149 fee for the Connect + package when our "trial" period ends? Is Rivian going to keep our modems going with an AT&T account on their dime or will it just have no connectivity without someone paying AT&T for service?

Less like Skynet, more like Colossus: The Forbin Project o_O
 

Sponsored

gultin

Well-Known Member
First Name
S
Joined
Sep 30, 2021
Threads
13
Messages
230
Reaction score
354
Location
CO
Vehicles
R1T
I wonder if our vehicles will continue sending all that data if we make it "forget" our home networks or will it just find another route and send it via LTE?

That's precisely why I'm very interested in what will happen connectivity wise if we don't pay the $149 fee for the Connect + package when our "trial" period ends? Is Rivian going to keep our modems going with an AT&T account on their dime or will it just have no connectivity without someone paying AT&T for service?

Less like Skynet, more like Colossus: The Forbin Project o_O
I had actually tried turning off WiFi for a few days to see if it helps with vampire drain, (that's been significantly higher since the last update and I'm seeing 5-6% loss every 24 hours), but it made no difference.
 

NY_Rob

Well-Known Member
First Name
Rob
Joined
Feb 9, 2022
Threads
23
Messages
5,417
Reaction score
7,997
Location
long island
Vehicles
Model 3 LR AWD, BMW i3 REX, 2024 Rubicon 4xe
Occupation
IT
I had actually tried turning off WiFi for a few days to see if it helps with vampire drain, (that's been significantly higher since the last update and I'm seeing 5-6% loss every 24 hours), but it made no difference.
Thanks... so it simply switched to LTE to send data, nice..:(

As I mentioned above, it will be interesting to see what Rivian is going to do with those of us who are not going to subscribe to Connect +. It would be ironic indeed if canceling Driver + (and making your Rivian forget your home network) mitigated vampire drain :D
Rivian would really be painting themselves in to a corner at that point!
 

FooF

Well-Known Member
First Name
FooF
Joined
Feb 24, 2023
Threads
9
Messages
950
Reaction score
1,349
Location
Mountain View CA
Website
foof.me
Vehicles
2022 R1S Launch Green
Occupation
DJ
Clubs
 
Maybe try allowing the traffic and see if your drain decreases?
 

Lopsed

New Member
First Name
Brett
Joined
Aug 31, 2024
Threads
0
Messages
3
Reaction score
1
Location
Oak Park
Vehicles
Rivian R1T
I wonder if our vehicles will continue sending all that data if we make it "forget" our home networks or will it just find another route and send it via LTE?

That's precisely why I'm very interested in what will happen connectivity wise if we don't pay the $149 fee for the Connect + package when our "trial" period ends? Is Rivian going to keep our modems going with an AT&T account on their dime or will it just have no connectivity without someone paying AT&T for service?

Less like Skynet, more like Colossus: The Forbin Project o_O
I don't know what will happen...but I want to unsubscribe from this subscription in the future too.
 

Zoidz

Well-Known Member
First Name
Gil
Joined
Feb 28, 2021
Threads
226
Messages
5,199
Reaction score
11,701
Location
PA
Vehicles
23 R1S Adv, Avalanche, BMWs-X3,330cic,K1200RS bike
Occupation
Engineer
Your S has become sentient and is taking its first steps. It’s Skynet all over again….
How we imagined AI vs. today's reality:

Rivian R1T R1S Rivian Constantly sending Buffer Overflow traffic to AWS 1725117118612-4f

Rivian R1T R1S Rivian Constantly sending Buffer Overflow traffic to AWS 1725117206765-r
 

Sponsored

BCondrey

Well-Known Member
First Name
Barry
Joined
Dec 12, 2021
Threads
0
Messages
700
Reaction score
710
Location
Richmond, VA
Vehicles
R1T
Occupation
IT
I think you can safely permit this, or turn off the detection of the CVE. This is to protect against malformed addresses causing buffer overflows. Chances are your Rivian is not going to hack the AWS. I would be more concerned about the uploads failing all the time. u-blox is the marker for the MAC, correct.
 

Osyras

Well-Known Member
First Name
Danny
Joined
Aug 3, 2023
Threads
29
Messages
340
Reaction score
323
Location
Ontario, Canada
Vehicles
Gen 2 R1S Large pack.
Clubs
 
Hello,

I was looking at my local network today, and I noticed that a device on my network is constantly being denied due to an IPS rule. Specifically in the Buffer Overflow Category with the name "SSL OpenSSL CRL Verification X.400 Address Handling Type Confusion Vulnerability (CVE-2023-0286)" Here is a link to the details of this detection in my WatchGuard appliance: https://securityportal.watchguard.com/threats/detail?ruleId=1231758

After some digging, I found that this appears to be my R1S with a MAC address that is associated with Vendor "u-blox ag" (OUI 20:BA:36). All of the traffic appears to be going to destination IP addresses that are associated with AWS. Additionally, it appears DNS lookups occur for "v1authz.prod.rivianservices.com" in the same cycle of the events.

Granted, my home setup also doubles as my lab, so I am sure I am unique in seeing this as most home users may not notice. That being said, I am posting here to see if anyone else has happened to see this on their network or if they have any insight. Definitely a discussion topic. I will likely also contact Rivian about this as well.

Thanks!

Out of curiosity, what tools are you using to capture the traffic? I have a lot of network experience and am very familiar with tools like wireshark, but none of it is in the monitoring side.

Tx

Danny
 
OP
OP

PurseChicken

Member
Joined
Sep 4, 2023
Threads
1
Messages
15
Reaction score
9
Location
Oregon
Vehicles
2024 R1S
Can you check your logs to determine when this started? Does it coincide with the update release?
Unfortunately, the logs on these were so great that they were just overwriting the log file. So basically, I can't go back far enough to determine if this was a last update issue of if it has been present for some time before that.

I think you can safely permit this, or turn off the detection of the CVE. This is to protect against malformed addresses causing buffer overflows. Chances are your Rivian is not going to hack the AWS. I would be more concerned about the uploads failing all the time. u-blox is the marker for the MAC, correct.
The risk here is less that my Rivian is going to "hack the AWS", however I am more concearned about malicious looking traffic egressing my network and being inspected as such on the AWS side. Not only is this bad hygiene, but it has the potential for ending up on block lists \ ban lists.

Out of curiosity, what tools are you using to capture the traffic? I have a lot of network experience and am very familiar with tools like wireshark, but none of it is in the monitoring side.

Tx

Danny
Its not too complex on my side. I just have IPS enabled on my ingress and egress traffic with my firewall. It is what logs the events and signatures for analyzing later or in real time.
 

godfodder0901

Well-Known Member
First Name
Jared
Joined
Mar 12, 2019
Threads
27
Messages
5,765
Reaction score
10,152
Location
Washington
Vehicles
2022 Rivian R1T LE
Unfortunately, the logs on these were so great that they were just overwriting the log file. So basically, I can't go back far enough to determine if this was a last update issue of if it has been present for some time before that.



The risk here is less that my Rivian is going to "hack the AWS", however I am more concearned about malicious looking traffic egressing my network and being inspected as such on the AWS side. Not only is this bad hygiene, but it has the potential for ending up on block lists \ ban lists.



Its not too complex on my side. I just have IPS enabled on my ingress and egress traffic with my firewall. It is what logs the events and signatures for analyzing later or in real time.
I wouldn't be too concerned. I've never seen an IDS/IPS that didn't throw false positives from time to time. FWIW I'm not getting any malicious packets flagged through Snot/Suricata.
Sponsored

 
 








Top