Bosch Infotainment ECU
cpe:2.3:o:bosch:cpp7.3_firmware:*:*:*:*:*:*:*, +3 more
- 283C30861E
A vulnerability exists in the Bosch-manufactured infotainment ECU of the 2020 Nissan Leaf ZE1, related to the Redbend service used for over-the-air updates. The issue arises because the default SSL configuration does not properly verify server certificates, allowing an attacker to impersonate a Redbend server with a self-signed certificate. This could enable unauthorized access to the vehicle's update system and potentially exploit other vulnerabilities within the ECU.
Exploitation of this vulnerability could lead to a Man-in-the-Middle (MitM) attack, allowing an attacker to intercept and manipulate data between the infotainment system and the Redbend server. This could include injecting malicious update data or provisioning information.
The vulnerability can be reproduced by establishing a Bluetooth connection with the Nissan Leaf infotainment system and then initiating a hands-free profile communication. This process can be automated with a script that bypasses the anti-theft mechanism and exploits the stack buffer overflow vulnerability in the Bluetooth stack, leading to remote code execution on the infotainment ECU.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.