⌘K
HomeRecallsInvestigations RQ15004
NHTSA defect investigation · Recall Query

Ram, Jeep and 3 others recall query RQ15004

Software security vulnerability. NHTSA’s Office of Defects Investigation opened this recall query about the software on 29 model years (2013–2015). Opened Jul 24, 2015, closed Jan 5, 2016 after 5 months. It concerns recall 15V508000. closed

What NHTSA says

Source: Office of Defects Investigation, as filed

On July 23, 2015, Fiat Chrysler Automobiles (FCA) launched Safety Recall 15V-461 to remedy security vulnerabilities in approximately 1.4 million model year (MY) 2013 through 2015 vehicles equipped with Uconnect head units (HU) 8.4A (RA3 radio) and 8.4AN (RA4 radio) manufactured by Harman International. On July 24, 2015, the Office of Defects Investigation (ODI) opened Recall Query, RQ 15-004, to investigate HU security vulnerabilities and remedy effectiveness in the recalled population and to determine whether similar units have been supplied for use in other FCA vehicles. In an August 11, 2015 letter, FCA submitted a second Part 573 safety recall report expanding the scope of the Uconnect RA4 model radio to include additional 7,810 MY 2015 Jeep Renegade vehicles manufactured from September 18, 2014 through June 25, 2015 (Recall 15V-508).Scope analysis indicated that Uconnect radios installed in FCA vehicles not included in recalls 15V-461 or 15V-508 (subject recalls) are not equipped with built-in cellular access or short range wireless communication features and, thus, do not contain the security vulnerabilities addressed by the subject recalls. SUBJECT VEHICLES: MY2014 through 2015 Dodge Durango, Jeep Grand Cherokee and Jeep Cherokee sport utility vehicles; MY2013 through 2015 Ram 1500, 2500, 3500 and 4500/5500 pickup trucks; MY2013 through 2015 Dodge Viper vehicles; and MY2015 Chrysler 200, 300, Jeep Renegade, Dodge Charger and Challenger vehicles. According to FCA, long and short range wireless vulnerabilities identified in the recalled vehicles could allow unauthorized third-party access to, and manipulation of, networked vehicle control systems. Successful exploitation of the vulnerabilities, coupled with reverse engineering of networked microprocessor control modules, could result in unauthorized manipulation of vehicle control systems. This unauthorized manipulation of vehicle controls and systems could expose the driver, vehicle occupants or other highway users to an increased risk of injury. FCA and its network provider, Sprint, conducted a nationwide campaign to block access to a radio communications port that was unintentionally left open. On July 27, 2015, short range wireless vulnerabilities were also blocked. Finally, third party security evaluation and regression testing identified vulnerabilities that were either remedied by Sprint or through updates to the FCA Uconnect software. ODI identified a total of 30 complaints or field reports on unique vehicles submitted by FCA (29) or received by NHTSA (1) alleging incidents of theft from a vehicle or anomalous performance that the owner alleged were caused by, or may have been caused by, remote hacking. Twenty-six (87%) of these reports were submitted after a magazine article was published on July 21, 2015, describing the remote hacking of an FCA vehicle by researchers who were able to affect the operation of various vehicle control systems, including the service brakes, steering, throttle and ignition. Most of the complaints involved vehicle systems that were not safety critical (e.g., complaints related to radio, navigation system, or air-conditioning control) and did not affect vehicle control. Three complaints reported engine stalls. One owner reported sudden unintended acceleration allegedly related to hacking. None of the complaints or field reports reviewed involved the steering and braking vehicle control effects demonstrated by the research hackers prior to the recall. There were no confirmed incidents of hacking in any of the records reviewed by ODI. The remedies completed by Sprint and FCA appear to have eliminated vulnerabilities that mi

Stage Recall Query — NHTSA works to complete one within eight months Opened Jul 24, 2015 Closed Jan 5, 2016 Manufacturer Chrysler (FCA US, LLC) Components Electrical System › Software Recall under query 15V508000

A Recall Query is a look at a recall that already exists — whether its remedy works, whether it reached every vehicle it should have, whether the manufacturer met its obligations. The summary is the agency’s own text from its investigation file, unedited; the opening and closing resumes with the full reasoning are on NHTSA’s site under this number.

What this means for an owner

Source: and what happens next

An investigation is not a finding that a defect exists, and it puts no duty on anyone. NHTSA opens a Preliminary Evaluation when complaints and other reports suggest a condition worth asking the manufacturer about; it upgrades to an Engineering Analysis when the answers warrant testing; it closes either when it recommends a recall, when the manufacturer recalls on its own, or when no defect trend is found. The agency’s own goals are about four months for a petition, eight for a Preliminary Evaluation or a Recall Query and eighteen for an Engineering Analysis; many run longer.

This one is closed. A recall query ends with NHTSA’s finding on the recall it examined — the remedy stands, is widened, or a new campaign follows; the file names the recall it concerned and NHTSA’s closing resume carries the reasoning.

Model years it names

Source: as NHTSA filed them

Also named: 2015 Chrysler 200; 2015 Chrysler 300; 2015 Dodge Challenger; 2015 Dodge Charger; 2014 Dodge Durango; 2015 Dodge Durango; 2014 Jeep Cherokee; 2015 Jeep Cherokee; 2014 Jeep Grand Cherokee; 2015 Jeep Grand Cherokee; 2015 Jeep Renegade; 2013 Ram 1500; 2014 Ram 1500; 2015 Ram 1500; 2013 Ram 2500; 2014 Ram 2500; 2015 Ram 2500; 2013 Ram 3500; 2014 Ram 3500; 2015 Ram 3500; 2013 Ram 4500; 2014 Ram 4500; 2015 Ram 4500; 2013 Ram 5500; 2014 Ram 5500; 2015 Ram 5500; 2013 SRT Viper; 2014 SRT Viper; 2015 SRT Viper.

A vehicle page’s investigation list carries the same action; a name here is the scope NHTSA opened, not a list of affected VINs.

Common questions

Source: NHTSA Office of Defects Investigation

Is RQ15004 a recall?

No — it is NHTSA’s examination of recall 15V508000, which has its own page and remedy.

Is RQ15004 still open?

No. It closed on Jan 5, 2016 with its finding on recall 15V508000.

Which vehicles does RQ15004 cover?

NHTSA opened it on 29 model years: 2015 Chrysler 200, 2015 Chrysler 300, 2015 Dodge Challenger, 2015 Dodge Charger, 2014 Dodge Durango, 2015 Dodge Durango and more. That is the scope of the inquiry, not a list of affected vehicles; a recall, if one follows, defines its own population by VIN.