Multiple Vulnerabilities in the Mazda In-Vehicle Infotainment (IVI) System
ID: 89971f06-b2cb-52a3-b51d-14d2a8881cef
STIX ID: report--89971f06-b2cb-52a3-b51d-14d2a8881cef
Feed Name: Zero Day Initiative (ZDI) Blog
This report analyzes the update mechanism for an embedded system, detailing the structure of password-protected update ZIPs (including root filesystem, kernel, bootloaders, and a passwd replacement) and describing the verification workflow that extracts certificates and verifies signatures. It notes that substantial processing of the supplied update file occurs before integrity checks and that researchers could not produce signed malicious updates or find a verification bypass during the investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
