6 Infotainment Bugs Allow Mazdas to Be Hacked With USBs
ID: fe26d02c-ae01-5040-b579-e9c9e0afcfc7
STIX ID: report--fe26d02c-ae01-5040-b579-e9c9e0afcfc7
Feed Name: Dark Reading
Six unpatched vulnerabilities were disclosed in Mazda's in-vehicle infotainment (Mazda Connect CMU) affecting recent Mazda models; the flaws—path/file sanitization issues, SQL injection via device serial number, unauthenticated SoC boot, and missing firmware verification on the VIP MCU—can enable full IVI compromise and, in ZDI research, a pivot to the vehicle CAN bus. All issues require physical insertion of a malicious USB, remain unpatched with no CVSS scores yet, and there is no reported evidence of in-the-wild exploitation, though the potential safety impact is significant if abused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
