CVE-2020-8539
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon, to trigger unintended functionalities. In addition, this executable may be used by an attacker to inject commands to generate CAN frames that are sent into the M-CAN bus (Multimedia CAN bus) of the vehicle.
Kia Motors Head Unit con versión de Software: SOP.003.30.18.0703, SOP.005.7.181019 y SOP.007.1.191209, pueden permitir a un atacante inyectar comandos no autorizados, mediante la ejecución del demonio del ejecutable micomd, para activar funciones no deseadas. Además, este ejecutable puede ser usado por un atacante para inyectar comandos para generar tramas CAN que se envían al bus M-CAN (bus Multimedia CAN) del vehículo
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-03 CVE Reserved
- 2020-12-01 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-11-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-276: Incorrect Default Permissions
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://gist.github.com/gianpyc/4dc8b0d0c29774a10a97785711e325c3 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://sowhat.iit.cnr.it/pdf/IIT-20-2020.pdf | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kia Search vendor "Kia" | Head Unit Firmware Search vendor "Kia" for product "Head Unit Firmware" | sop.003.30.18.0703 Search vendor "Kia" for product "Head Unit Firmware" and version "sop.003.30.18.0703" | - |
Affected
| in | Kia Search vendor "Kia" | Head Unit Search vendor "Kia" for product "Head Unit" | - | - |
Safe
|
Kia Search vendor "Kia" | Head Unit Firmware Search vendor "Kia" for product "Head Unit Firmware" | sop.005.7.181019 Search vendor "Kia" for product "Head Unit Firmware" and version "sop.005.7.181019" | - |
Affected
| in | Kia Search vendor "Kia" | Head Unit Search vendor "Kia" for product "Head Unit" | - | - |
Safe
|
Kia Search vendor "Kia" | Head Unit Firmware Search vendor "Kia" for product "Head Unit Firmware" | sop.007.1.191209 Search vendor "Kia" for product "Head Unit Firmware" and version "sop.007.1.191209" | - |
Affected
| in | Kia Search vendor "Kia" | Head Unit Search vendor "Kia" for product "Head Unit" | - | - |
Safe
|