Defect Petition · Closed
SAE J1939 Data Bus Vulnerability
Manufacturer: Generic Manufacturer
What NHTSA is examining
In a letter dated September 27, 2021, Mr. James Lamb, Executive Director of the Small Business in Transportation Coalition (SBTC), petitioned the National Highway Traffic Safety Administration (NHTSA), requesting the initiation of a defect investigation into the potential hacking susceptibility of the Society of Automotive Engineers (SAE) J1939 Data Bus standard. SAE J1939 is the vehicle bus recommended practice used for communication and diagnostics among vehicle components. In support of the petition, the petitioner cited a study from University of Michigan (Michigan) researchers alleging a SAE J1939 Data Bus vulnerability in a Model Year (MY) 2001 school bus and a MY 2006 Class-8 semi-tractor. The study alleges that, due to the vulnerability, vehicle critical safety functions such as the accelerator control or braking systems are susceptible to unauthorized access and control and increases risk to motor vehicle safety. On December 23, 2021, the Office of Defects Investigation (ODI) opened DP21-005 to evaluate the petitioner's request. The petitioner did not specify the make and model of the vehicles with the alleged safety defect. The only categories of relevant vehicles specified were found in the study: MY 2001 school buses and MY 2006 Class-8 semi-tractors. ODI has not received any complaints of any type related to this alleged vulnerability (The single complaint identified above is the petition.). This evaluation included searches of complaints from vehicle owners…
Vehicles under investigation
Source: NHTSA Office of Defects Investigation records, updated daily. An investigation is not a determination that a defect exists; many probes close without a recall.