logo

Unpatched Mazda Connect bugs let hackers install persistent malware

ID: 58253750-cfd7-5106-9ddd-35e8ad8d362c

STIX ID: report--58253750-cfd7-5106-9ddd-35e8ad8d362c

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-11-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Trend Micro ZDI disclosed six unpatched vulnerabilities in Mazda Connect infotainment units (firmware 74.00.324A) — CVE-2024-8355, CVE-2024-8359, CVE-2024-8360, CVE-2024-8358, CVE-2024-8357, and CVE-2024-8356 — that include SQL injection, multiple command injection flaws, a missing root of trust, and unsigned MCU code; an attacker with physical access (e.g., USB and potentially vehicle key according to Mazda) can deploy crafted updates within minutes to gain root-level code execution, persistence, and potential access to vehicle CAN buses and ECUs, posing safety and operational risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.