The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically proximate attackers to execute arbitrary code because some unsigned parts of a metainfo file are parsed, which can cause attacker-controlled files to be written to the infotainment system and executed as root.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-21054 The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically proximate attackers to execute arbitrary code because some unsigned parts of a metainfo file are parsed, which can cause attacker-controlled files to be written to the infotainment system and executed as root.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T16:40:59.805Z

Reserved: 2020-11-16T00:00:00

Link: CVE-2020-28656

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-16T04:15:12.790

Modified: 2024-11-21T05:23:06.833

Link: CVE-2020-28656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.