Vulnerability Description
A lack of exception handling in the Renault Easy Link Multimedia System Software Version 283C35519R allows attackers to cause a Denial of Service (DoS) via supplying crafted WMA files when connecting a device to the vehicle's USB plug and play feature.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Renault | Easy Link | 283c35519r |
| Renault | Zoe Ev 2021 | - |
Related Weaknesses (CWE)
References
- https://github.com/zj3t/Automotive-vulnerabilities/blob/main/RENAULT/ZOE_EV_2021ExploitThird Party Advisory
- https://github.com/zj3t/Automotive-vulnerabilities/blob/main/RENAULT/ZOE_EV_2021ExploitThird Party Advisory
FAQ
What is CVE-2023-39801?
CVE-2023-39801 is a vulnerability with a CVSS score of 4.6 (MEDIUM). A lack of exception handling in the Renault Easy Link Multimedia System Software Version 283C35519R allows attackers to cause a Denial of Service (DoS) via supplying crafted WMA files when connecting ...
How severe is CVE-2023-39801?
CVE-2023-39801 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-39801?
Check the references section above for vendor advisories and patch information. Affected products include: Renault Easy Link, Renault Zoe Ev 2021.