A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitive details such as diagnostic log traces, system logs, headunit passwords, and personally identifiable information (PII). The exposure of such information may have serious implications for user privacy and system integrity.
History

Wed, 06 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Globalsuzuki
Globalsuzuki smartplay Headunit Firmware
Weaknesses CWE-922
CPEs cpe:2.3:o:globalsuzuki:smartplay_headunit_firmware:*:*:*:*:*:*:*:*
Vendors & Products Globalsuzuki
Globalsuzuki smartplay Headunit Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitive details such as diagnostic log traces, system logs, headunit passwords, and personally identifiable information (PII). The exposure of such information may have serious implications for user privacy and system integrity.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-09-18T00:00:00

Updated: 2024-11-05T19:28:34.301Z

Reserved: 2024-06-24T00:00:00

Link: CVE-2024-39339

cve-icon Vulnrichment

Updated: 2024-09-19T16:56:16.167Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-18T20:15:03.197

Modified: 2024-11-06T20:35:19.170

Link: CVE-2024-39339

cve-icon Redhat

No data.