Go top
Paper information

Highway to Hack - Security gaps in ETSI ITS standards

R. Gesteira-Miñarro, T. Yoshizawa, R. Palacios, G. López

Computer Standards & Interfaces Vol. 97, pp. 104133

Summary:

Vehicle-to-Everything (V2X) communication technologies are revolutionizing transportation by enabling real-time information exchange among vehicles, infrastructure, pedestrians, and networks. While these technologies offer significant benefits in terms of road safety, traffic efficiency, and support for autonomous driving, they also introduce critical security and privacy risks due to their decentralized and dynamic nature. In this paper, we perform an analysis of the ETSI Intelligent Transport System (ITS) standards, specifications and reports to identify vulnerabilities that could be exploited to cause cyber–physical damages. We focus particularly on Cooperative Awareness Messages (CAM) and Decentralized Environmental Notification Messages (DENM) in the ETSI ITS standard, and pseudonym ID mechanisms. We identified several security issues, including vulnerabilities that lead to replay attacks, identity-based attacks such as spoofing and Sybil attacks, as well as grayhole attacks. We present attack scenarios where the issues found can be leveraged to compromise road safety, and quantify their potential impact through simulations using Eclipse SUMO. These scenarios might be relevant during a transition period where V2X-enabled vehicles coexist with legacy vehicles. Furthermore, we propose mitigations to address the identified issues. Our findings highlight the need for stronger security measures in V2X systems to ensure both safety and security in future intelligent transportation systems.


Spanish layman's summary:

En este artículo se analizan los estándares ETSI ITS de V2X para identificar vulnerabilidades de seguridad y privacidad en CAM, DENM y los mecanismos de pseudónimos. Mostramos cómo los ataques de replay, spoofing, Sybil y grayhole pueden afectar la seguridad vial, los evaluamos mediante simulaciones con SUMO y proponemos mitigaciones.


English layman's summary:

This paper analyzes ETSI ITS V2X standards to uncover security and privacy vulnerabilities in CAM, DENM, and pseudonym mechanisms. We show how replay, spoofing, Sybil, and grayhole attacks can impact road safety, evaluate them via SUMO simulations, and propose mitigations.


Keywords: Cooperative awareness; Vehicle-to-everything; Replay attack; Pseudonym; Simulation; Cybersecurity


JCR-JIF Impact Factor and WoS quartile: 4,600 - Q1 (2025)

DOI reference: DOI icon https://doi.org/10.1016/j.csi.2026.104133

Published on paper: April 2026.

Published on-line: January 2026.



Citation:
R. Gesteira-Miñarro, T. Yoshizawa, R. Palacios, G. López, "Highway to Hack - Security gaps in ETSI ITS standards", Computer Standards & Interfaces, Vol. 97, pp. 104133, April 2026. [Online: January 2026] doi: 10.1016/j.csi.2026.104133

    Research topics:
  • Safe, Trustworthy, Fair and Interpretable AI
    Research groups:
  • Instituto de Investigación Tecnológica (IIT)
    ODS:
  • Goal 9: Industry, innovation and infrastructure
  • Goal 11: Sustainable cities and communities

pdf Preview
Request Request the document to be emailed to you.