CVE-2020-8539
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon, to trigger unintended functionalities.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon, to trigger unintended functionalities. In addition, this executable may be used by an attacker to inject commands to generate CAN frames that are sent into the M-CAN bus (Multimedia CAN bus) of the vehicle.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.32% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- kia/head unit firmware
- Source
- cve@mitre.org
References
- https://gist.github.com/gianpyc/4dc8b0d0c29774a10a97785711e325c3Third Party Advisory
- https://sowhat.iit.cnr.it/pdf/IIT-20-2020.pdfExploit, Third Party Advisory
- https://gist.github.com/gianpyc/4dc8b0d0c29774a10a97785711e325c3Third Party Advisory
- https://sowhat.iit.cnr.it/pdf/IIT-20-2020.pdfExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.