---
title: "CAN and CAN FD Security Threats and Attack Vectors"
canonical_url: https://can-security.net/threats/
description: "Physical bus access, frame injection, replay, ID spoofing, denial of service, and remote entry: CAN and CAN FD threat categories with CVSS v4.0 baselines."
last_updated: 2026-08-27
---
# Threats and Attack Vectors on CAN and CAN FD Networks

This page surveys the threats facing CAN and CAN FD systems. Threats are grouped by attack surface and accompanied by [CVSS](https://can-security.net/resources/terms-and-definitions/#term-cvss) v4.0 baseline scores derived in EmSA-WP-103. Each category links to a deeper page with detailed analysis and the corresponding mitigations.

## Categories of CAN Bus Threats

Threats to CAN and CAN FD systems fall into three broad categories:  
[Protocol Weaknesses](https://can-security.net/threats/protocol-weaknesses/) (inherent to the bus), [Physical Access](https://can-security.net/threats/physical-access/), and [Remote Attack](https://can-security.net/threats/remote-attack/) via gateways and diagnostic ports.  
Real-world attacks usually combine several of these, for example remote entry through a maintenance gateway followed by frame injection or replays enabled by the protocol's lack of authentication.

## Threat Categories and CVSS Baseline

The following table summarizes each threat category against an unprotected classical CAN node. Default CVSS v4.0 baseline for an unprotected CAN node: `5.2 / Medium` with vector `CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N` (source: EmSA-WP-103).

| Threat | Attack Vector | CVSS baseline | Detail |
| --- | --- | --- | --- |
| Gateway / service-interface compromise | Network or Adjacent | Higher than baseline | [Remote Attack →](https://can-security.net/threats/remote-attack/) |
| Replay attacks | Physical or Network | 5.2 / Medium | [Protocol Weaknesses →](https://can-security.net/threats/protocol-weaknesses/) |
| Frame injection / spoofing | Physical or Network | 5.2 / Medium | [Protocol Weaknesses →](https://can-security.net/threats/protocol-weaknesses/) |
| Physical bus tapping / sniffing | Physical | Low (no integrity impact) | [Physical Access →](https://can-security.net/threats/physical-access/) |
| Bus flooding / DoS* | Physical | 5.2 / Medium | [Physical Access →](https://can-security.net/threats/physical-access/) |

* Bus flooding / DoS may often be classified as sabotage rather than a cybersecurity attack: like cutting wires, it disrupts global communication without targeting a specific device or function.

## How Threats Relate to IEC 62443 Security Levels

IEC 62443 frames threats by attacker capability:  
[SL1](https://can-security.net/resources/terms-and-definitions/#term-sl) (incidental misuse),  
[SL2](https://can-security.net/resources/terms-and-definitions/#term-sl) (intentional, low resources),  
[SL3](https://can-security.net/resources/terms-and-definitions/#term-sl) (intentional, moderate resources with technology-specific skills) and  
[SL4](https://can-security.net/resources/terms-and-definitions/#term-sl) (intentional, extended resources with technology-specific skills).  
Most CAN attack scenarios in practice map to SL2 or SL3. The defensive response is layered, since no single control covers all of these threats. Note that even an attacker with low resources might have access to commercially available "diagnostic devices" that support pre-loaded attack scenarios (like opening a vehicle's doors or starting an engine).  
[IEC 62443](https://can-security.net/resources/iec-62443-sl2-requirements/)

> ### EmSA Training — CAN Threats & Defences

> Class on CAN-specific cybersecurity characteristics: why CAN's threat model differs from generic IT, the lack of native authentication, physical exposure, broadcasting and spoofing, denial-of-service via bus flooding, and protective techniques both with and without cryptography.

> [Open this course →](https://emsa.courses/course/can-threats-defences)

## Frequently Asked Questions

### Can CAN be attacked remotely?

Not directly. CAN itself is a physical-medium bus. However, almost every modern CAN network is reachable indirectly via a gateway, remote-service interface, diagnostic port or wireless maintenance link. Once that boundary is crossed, the attacker has the same capabilities as a physically attached node. See [Remote attack](https://can-security.net/threats/remote-attack/).

### What is frame injection on a CAN bus?

Frame injection is the transmission of CAN frames with arbitrary CAN IDs by a node that should not legitimately use those IDs. Because CAN has no authentication, receiving nodes cannot tell legitimate frames from injected ones. See [Protocol weaknesses](https://can-security.net/threats/protocol-weaknesses/).

### How hard is it to attack a physically enclosed CAN system?

Hard, but not impossible. Service technicians, supply-chain insiders and devices added post-deployment (if wires are exposed, it only takes seconds to attach a sniffer) are common physical-access attack vectors. CVSS v4.0 with AV:P captures this; the score is non-zero precisely because physical access is feasible, not impossible.
