CVE-2023-26243
Last modified
CVE-2023-26243 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt firmware files has an information leak that allows an attacker to read the AES key and initialization vector from memory. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt firmware files has an information leak that allows an attacker to read the AES key and initialization vector from memory. An attacker may exploit this to create custom firmware that may be installed in the IVI system. Then, an attacker may be able to install a backdoor in the IVI system that may allow him to control it, if it is connected to the Internet through Wi-Fi.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hyundai | Gen5w L Firmware | ae_e_pe_eur.s5w_l001.001.211214 |
References
- https://sowhat.iit.cnr.itNot Applicable
- https://sowhat.iit.cnr.it:8443/can-work/chimaeraExploit, Third Party Advisory
- https://sowhat.iit.cnr.it:8443/can-work/chimaera/-/blob/main/Report/IIT-01-2023.pdfExploit, Third Party Advisory
- https://sowhat.iit.cnr.itNot Applicable
- https://sowhat.iit.cnr.it:8443/can-work/chimaeraExploit, Third Party Advisory
- https://sowhat.iit.cnr.it:8443/can-work/chimaera/-/blob/main/Report/IIT-01-2023.pdfExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-26243?
How severe is CVE-2023-26243?
How do I fix CVE-2023-26243?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-26236An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due …7.8
- CVE-2023-26237An issue was discovered in WatchGuard EPDR 8.0.21.0002. It i…6.7
- CVE-2023-26238An issue was discovered in WatchGuard EPDR 8.0.21.0002. It i…5.5
- CVE-2023-26239An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due …5.5
- CVE-2023-2624The KiviCare WordPress plugin before 3.2.1 does not sanitise…6.1
- CVE-2023-26242afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region…7.8
- CVE-2023-26244An issue was discovered in the Hyundai Gen5W_L in-vehicle in…7.8
- CVE-2023-26245An issue was discovered in the Hyundai Gen5W_L in-vehicle in…7.8
- CVE-2023-26246An issue was discovered in the Hyundai Gen5W_L in-vehicle in…7.8
- CVE-2023-26248The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used…5.3
- CVE-2023-26249Knot Resolver before 5.6.0 enables attackers to consume its …7.5
- CVE-2023-2625A vulnerability exists that can be exploited by an authentic…8
Are you affected by CVE-2023-26243?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
