Vulnerability Description
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon, to trigger unintended functionalities. In addition, this executable may be used by an attacker to inject commands to generate CAN frames that are sent into the M-CAN bus (Multimedia CAN bus) of the vehicle.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kia | Head Unit Firmware | sop.003.30.18.0703 |
| Kia | Head Unit | - |
Related Weaknesses (CWE)
References
- https://gist.github.com/gianpyc/4dc8b0d0c29774a10a97785711e325c3Third Party Advisory
- https://sowhat.iit.cnr.it/pdf/IIT-20-2020.pdfExploitThird Party Advisory
- https://gist.github.com/gianpyc/4dc8b0d0c29774a10a97785711e325c3Third Party Advisory
- https://sowhat.iit.cnr.it/pdf/IIT-20-2020.pdfExploitThird Party Advisory
FAQ
What is CVE-2020-8539?
CVE-2020-8539 is a vulnerability with a CVSS score of 7.8 (HIGH). Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon,...
How severe is CVE-2020-8539?
CVE-2020-8539 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8539?
Check the references section above for vendor advisories and patch information. Affected products include: Kia Head Unit Firmware, Kia Head Unit.