CVE-2023-39075
Last modified
CVE-2023-39075 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. Renault Zoe EV 2021 automotive infotainment system versions 283C35202R to 283C35519R (builds 11.10.2021 to 16.01.2023) allows attackers to crash the infotainment system by sending arbitrary USB data via a USB device.. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
Renault Zoe EV 2021 automotive infotainment system versions 283C35202R to 283C35519R (builds 11.10.2021 to 16.01.2023) allows attackers to crash the infotainment system by sending arbitrary USB data via a USB device.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Renault | Zoe Ev 2021 Firmware | >= 11.10.2021, <= 16.01.2023 |
References
- https://blog.jhyeon.dev/posts/vuln/202307/renault-zoe/Exploit, Third Party Advisory
- https://blog.jhyeon.dev/posts/vuln/202307/renault-zoe/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-39075?
How severe is CVE-2023-39075?
How do I fix CVE-2023-39075?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-39067Cross Site Scripting vulnerability in ZLMediaKiet v.4.0 and …6.1
- CVE-2023-39068Buffer Overflow vulnerability in NBD80S09S-KLC v.YK_HZXM_NBD…7.5
- CVE-2023-39069An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex …9.8
- CVE-2023-3907A privilege escalation vulnerability in GitLab EE affecting …8.8
- CVE-2023-39070An issue in Cppcheck 2.12 dev allows a local attacker to exe…7.8
- CVE-2023-39073An issue in SNMP Web Pro v.1.1 allows a remote attacker to e…9.8
- CVE-2023-39076Injecting random data into the USB memory area on a General …4.6
- CVE-2023-3908Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-39086ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmi…7.5
- CVE-2023-3909An issue has been discovered in GitLab CE/EE affecting all v…6.5
- CVE-2023-39094Cross Site Scripting vulnerability in ZeroWdd studentmanager…5.4
- CVE-2023-39096WebBoss.io CMS v3.7.0.1 contains a stored Cross-Site Scripti…5.4
Are you affected by CVE-2023-39075?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
