Filtered by vendor Visteon
Subscribe
Total
6 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-8355 | 1 Visteon | 1 Infotainment Firmware | 2024-12-19 | N/A | 6.8 MEDIUM |
|
Visteon Infotainment System DeviceManager iAP Serial Number SQL Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment system. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DeviceManager. When parsing the iAP Serial number, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can le ...
Show More |
|||||
| CVE-2024-8356 | 1 Visteon | 1 Infotainment | 2024-12-11 | N/A | 7.8 HIGH |
|
Visteon Infotainment VIP MCU Code Insufficient Validation of Data Authenticity Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Visteon Infotainment systems. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the firmware update process of the VIP microcontroller. The process does not properly ve ...
Show More |
|||||
| CVE-2024-8357 | 1 Visteon | 1 Infotainment | 2024-12-11 | N/A | 7.8 HIGH |
|
Visteon Infotainment App SoC Missing Immutable Root of Trust in Hardware Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Visteon Infotainment systems. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
The specific flaw exists within the configuration of the application system-on-chip (SoC). The issue results from the lack of properly con ...
Show More |
|||||
| CVE-2024-8358 | 1 Visteon | 1 Infotainment | 2024-12-11 | N/A | 6.8 MEDIUM |
|
Visteon Infotainment UPDATES_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the UPDATES_ExtractFile function. A crafted software update file can trigger execution of a system call composed from a user-supplied string. An attacker can leverage th ...
Show More |
|||||
| CVE-2024-8359 | 1 Visteon | 1 Infotainment | 2024-12-11 | N/A | 6.8 MEDIUM |
|
Visteon Infotainment REFLASH_DDU_FindFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the REFLASH_DDU_FindFile function. A crafted software update file can trigger execution of a system call composed from a user-supplied string. An attacker can leverage ...
Show More |
|||||
| CVE-2024-8360 | 1 Visteon | 1 Infotainment | 2024-12-04 | N/A | 6.8 MEDIUM |
|
Visteon Infotainment REFLASH_DDU_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the REFLASH_DDU_ExtractFile function. A crafted software update file can trigger execution of a system call composed from a user-supplied string. An attacker can lev ...
Show More |
|||||