VYPR

Infotainment

by Visteon

CVEs (6)

  • CVE-2024-8357HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Visteon Infotainment App SoC Missing Immutable Root of Trust in Hardware Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Visteon Infotainment systems. Although authentication is required to…

  • CVE-2024-8356HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Visteon Infotainment VIP MCU Code Insufficient Validation of Data Authenticity Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Visteon Infotainment systems. An attacker must first obtain the…

  • CVE-2024-8360MedNov 22, 2024
    risk 0.44cvss 6.8epss 0.01

    Visteon Infotainment REFLASH_DDU_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to…

  • CVE-2024-8359MedNov 22, 2024
    risk 0.44cvss 6.8epss 0.01

    Visteon Infotainment REFLASH_DDU_FindFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit…

  • CVE-2024-8358MedNov 22, 2024
    risk 0.44cvss 6.8epss 0.01

    Visteon Infotainment UPDATES_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit…

  • CVE-2024-8355MedNov 22, 2024
    risk 0.44cvss 6.8epss 0.01

    Visteon Infotainment System DeviceManager iAP Serial Number SQL Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment system. Authentication is not required to exploit this…