7.8
CVE-2020-8539
- EPSS 5.76%
- Veröffentlicht 01.12.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:59
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon, to trigger unintended functionalities. In addition, this executable may be used by an attacker to inject commands to generate CAN frames that are sent into the M-CAN bus (Multimedia CAN bus) of the vehicle.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kia ≫ Head Unit Firmware Versionsop.003.30.18.0703
Kia ≫ Head Unit Firmware Versionsop.005.7.181019
Kia ≫ Head Unit Firmware Versionsop.007.1.191209
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.76% | 0.901 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.