Website error exposes Ford customer data and more

Ford Dealership
(Image credit: Gopixa / Shutterstock)

Security researchers were able to access confidential company and employee records, customer databases, internal tickets and more on Ford's website due to a bug in the automaker's CRM software.

As reported by BleepingComputer, security researchers Robert Willis and break3r first discovered the vulnerability on the company's site before bringing in members of the ethical hacking group Sakura Samurai for additional help.

The bug itself, tracked as CVE-2021-27653, is an information exposure vulnerability that exists in misconfigured instances of Pega Infinity running on Ford's servers. In order to exploit it though, an attacker would first need to gain access to the backend web panel of a misconfigured Pega Chat Access Group portal instance. 

In a blog post, Robert Willis provided further insight on the impact of the vulnerability and how it allowed the security researchers to perform account takeovers, saying:

“The impact was large in scale. Attackers could use the vulnerabilities identified in the broken access control and obtain troves of sensitive records, perform account takeovers, and obtain a substantial amount of data.”

Vulnerability disclosure

While the security researchers reported their findings to Pega back in February of this year and the company promptly addressed the vulnerability in their chat portal, Ford was not as cooperative when the issue was reported to the automaker through its HackerOne vulnerability disclosure program.

Sakura Samurai's John Jackson explained in an email to BleepingComputer that at one point Ford stopped answering the security researcher's questions. In fact, HackerOne had to intervene to get an initial response on their vulnerability submission to the company.

However, it wasn't until the security researchers tweeted about the vulnerability on Ford's website without mentioning any sensitive details before they heard back from HackerOne.

In the end though, the security researchers had to wait a full six months before disclosing the vulnerability themselves due to HackerOne's policy. It's worth noting that Ford doesn't have a bug bounty program so there was no monetary incentive for them to disclose the vulnerability. Instead, they did it out of concern for the automaker's customers.

At this time it is still unclear as to whether or not cybercriminals or any other third-party gained access to the sensitive company and customer data exposed on Ford's website as a result of the vulnerability.

Via BleepingComputer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Subaru Starlink
Hackers expose serious Subaru security flaws that allow them to remotely start cars
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
Volkswagen Lane Keep
Over 800,000 electric car owners and drivers may have had private info exposed online
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
A person at a laptop with a cybersecure lock symbol floating above it.
A worrying security flaw could have left Microsoft SharePoint users open to attack
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand