logo

Multiple Vulnerabilities in the Mazda In-Vehicle Infotainment (IVI) System

ID: 89971f06-b2cb-52a3-b51d-14d2a8881cef

STIX ID: report--89971f06-b2cb-52a3-b51d-14d2a8881cef

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
65/100

Date Published: 2024-11-07

Date Updated: 2026-05-01

Author: Dmitry Janushkevich

...
...

This report analyzes the update mechanism for an embedded system, detailing the structure of password-protected update ZIPs (including root filesystem, kernel, bootloaders, and a passwd replacement) and describing the verification workflow that extracts certificates and verifies signatures. It notes that substantial processing of the supplied update file occurs before integrity checks and that researchers could not produce signed malicious updates or find a verification bypass during the investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.