VulnerabilityModified
CVE-2023-39075
Renault Zoe EV 2021 automotive infotainment system versions 283C35202R to 283C35519R (builds 11.10.2021 to 16.01.2023) allows attackers to crash the infotainment system by sending arbitrary USB data via a USB device.
MEDIUM 4.6EPSS 0.51%
Does this matter?
Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.
Description
Renault Zoe EV 2021 automotive infotainment system versions 283C35202R to 283C35519R (builds 11.10.2021 to 16.01.2023) allows attackers to crash the infotainment system by sending arbitrary USB data via a USB device.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Affected
- renault/zoe ev 2021 firmware
- Source
- cve@mitre.org
References
- https://blog.dhjeong.kr/posts/automotive/2023/12/how-to-fuzzing-realcars/
- https://blog.dhjeong.kr/posts/vuln/202307/renault-zoe/
- https://blog.jhyeon.dev/posts/vuln/202307/renault-zoe/Exploit, Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-39075
- https://blog.dhjeong.kr/posts/automotive/2023/12/how-to-fuzzing-realcars/
- https://blog.dhjeong.kr/posts/vuln/202307/renault-zoe/
- https://blog.jhyeon.dev/posts/vuln/202307/renault-zoe/Exploit, Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-39075
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.