Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
cvelistv5medium Β· 6.9
cve-2026-61893
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically the IEC 60870-5-104 protocol library used for power grid and substation automation. An attacker can send a specially crafted message to cause an out-of-bounds read, potentially crashing the system or leaking sensitive memory contents. This is a high-severity issue that could disrupt production line operations or expose internal data in automotive factory environments.
cvelistv5medium Β· 6.9
cve-2026-63033
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically the MZ Automation lib60870 library used for IEC 60870-5-104 communication protocols. An attacker can send a specially crafted message that causes the system to read one byte beyond the allocated memory buffer, potentially leading to information disclosure or system instability. This is a serious security issue that could disrupt production line operations or expose sensitive manufacturing data.
cvelistv5medium Β· 6.9
cve-2026-66349
This vulnerability affects the IEC 61850 protocol library used in electric vehicle charging stations and smart grid equipment for substation automation and EV-to-grid communication. An attacker can send a specially crafted network message to crash the MMS server process, causing a denial-of-service that could disrupt charging operations or grid communication. This is a high-severity issue because it requires only network access to trigger and can halt critical energy infrastructure services.
nvdmedium Β· 6.8
cve-2026-16147
The ITE IT82xx2 USB device-controller driver in Zephyr mishandles multi-packet OUT transfers, allowing a physically attached USB host to trigger a use-after-free write and event-list corruption in kernel memory. An attacker controlling the USB host can cause a reliable denial of service and potentially corrupt adjacent memory buffers, since the driver continues writing host-controlled data into a buffer the upper stack may have already freed. This could be relevant where the IT82xx2 USB peripheral controller is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 6.8
cve-2026-53495
containerd, an open-source container runtime, has a flaw in its CRI plugin on Linux where repeated ExecSync calls can accumulate blocked processes and exhaust host memory, potentially causing the runtime to be killed and become unavailable until restarted. This could be relevant where containerd is deployed in automotive systems, for example in containerized workloads on vehicle or fleet infrastructure. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 6.8
cve-2026-42808
Bosch Sensortec COINES_SDK versions 2.0 through 2.11 contain a buffer overflow flaw in the host streaming API, where the software copies sensor data into a caller-provided buffer without checking that the buffer is large enough. A malicious or compromised hardware board connected via USB or BLE could stream excessive sensor samples to trigger this overflow on the host machine, causing a denial of service or potentially allowing arbitrary code execution. This could be relevant where COINES_SDK is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
csaf_cisamedium Β· 6.8
icsa-26-239-03
Rockwell Automation's OTTO Fleet Manager contains a vulnerability caused by weak password hashing, which could make it easier for an attacker to crack stored passwords if they obtain an unencrypted system backup. The vulnerability is not remotely exploitable and has no known public attacks, but it affects the Transportation Systems sector. This could be relevant where OTTO Fleet Manager is deployed in automotive or fleet operations, so confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.8
cve-2026-65086
NVIDIA OpenShell for Linux has a vulnerability in its sandbox exec handler that could allow an attacker to perform OS command injection, potentially leading to code execution, information disclosure, and data tampering. This could be relevant where NVIDIA OpenShell is deployed in automotive systems, though the advisory does not confirm such use. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 6.8
cve-2026-18267
The advisory describes a vulnerability in the Kenwood DNR1007XR device's firmware update process, where a physically present attacker can create a symbolic link to move a file to an arbitrary location and execute code with root privileges, without requiring authentication. The severity is not explicitly stated in the advisory, but the technical impact is full system compromise via arbitrary code execution. Since the Kenwood DNR1007XR is a specific automotive head unit, this directly affects vehicles where this device is installed. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.8
cve-2026-18849
IBM OpenBMC firmware versions FW1060.00 through FW1060.80 contain a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access could execute arbitrary code, impacting confidentiality, integrity, and availability. This could be relevant where IBM OpenBMC is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
csaf_siemensmedium Β· 6.8
ssa-751328
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically the Siemens LOGO! Soft Comfort software used to program and configure automation controllers. A local attacker with access to the software could extract a hardcoded encryption key to decrypt project files or bypass passwords, and also crack password hashes offline to gain unauthorized access to sensitive production logic and configurations. Siemens has released an updated version to fix these issues, and updating the software is strongly recommended to protect manufacturing operations.
fkie_nvdmedium Β· 6.8
cve-2026-13307
This vulnerability affects EV charging infrastructure including wallboxes, DC fast chargers, and charging station management systems, specifically the Autel MaxiCharger AC Elite Home charger. A physically present attacker with no authentication can send malicious USB packets to overflow a buffer and execute arbitrary code on the device. This is a critical flaw that could allow an attacker to take full control of the charger, potentially disrupting charging operations or causing physical damage.
fkie_nvdmedium Β· 6.8
cve-2026-13309
This vulnerability affects EV charging infrastructure including wallboxes, DC fast chargers, and charging station management systems. The flaw exists in the Autel MaxiCharger AC Elite Home charger's NFC interface, where a physically present attacker can send a crafted card response to overflow a stack-based buffer and execute arbitrary code without needing any authentication. This is a critical issue because it allows an attacker to take full control of the charger, potentially disrupting charging operations or causing physical damage.
fkie_nvdmedium Β· 6.8
cve-2026-7328
Caliptra is a security IP core used in automotive-grade chips for hardware root of trust in ADAS and gateway modules. This vulnerability in the Core Runtime Firmware allows a privileged local attacker to cause a denial of service by sending unverified mailbox commands, potentially disrupting critical vehicle functions. The severity is limited to availability, with any broader security impact depending on how the chip is integrated into the vehicle system.
nvdmedium Β· 6.7
cve-2026-58773
A missing bounds check in the link_load_gnss_image function of link_device.c could allow an out-of-bounds write, leading to local escalation of privilege, though an attacker would need System execution privileges. This could be relevant where this GNSS-related component is deployed in automotive systems, since GNSS is commonly used in vehicle navigation and telematics. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.7
cve-2026-20517
The advisory describes a use-after-free vulnerability in the MediaTek chipset component "geniezone" that could allow local escalation of privilege, but only if an attacker already holds System privilege. No user interaction is required for exploitation. This could be relevant where MediaTek chipsets are deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.7
cve-2026-20511
The advisory describes a use-after-free memory corruption vulnerability in SurfaceFlinger, a component of MediaTek chipsets. An attacker who has already gained System privilege could exploit this to achieve local escalation of privilege without user interaction. This could be relevant where MediaTek chipsets are deployed in automotive systems, such as in infotainment or other embedded platforms; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.7
cve-2026-20510
This advisory describes a vulnerability in camera middleware on MediaTek chipsets, where a double-free flaw could allow an attacker with existing System privileges to escalate their privileges locally, without requiring user interaction. The affected component is part of a chipset that could be used in automotive systems, but this is not confirmed by the advisory. This could be relevant where MediaTek chipsets are deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.7
cve-2026-20509
The advisory describes a vulnerability in the Power HAL component of MediaTek chipsets, where a missing bounds check could allow an out-of-bounds write. An attacker who already has System privilege could exploit this to achieve local escalation of privilege, with no user interaction required. This could be relevant where MediaTek chipsets are deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.7
cve-2026-20508
The advisory describes a privilege escalation vulnerability in the Power HAL component of MediaTek chipsets, caused by type confusion. A malicious actor who already has System privilege could exploit this to achieve local escalation of privilege without user interaction. This could be relevant where MediaTek chipsets are deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.7
cve-2026-20507
This advisory describes a use-after-free vulnerability in the Audio HAL component of MediaTek chipsets, which could allow a malicious actor with existing System privileges to escalate their privileges locally without user interaction. The severity is not explicitly stated, but the technical impact is local privilege escalation. This could be relevant where MediaTek chipsets are deployed in automotive systems, so confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.7
cve-2026-20506
This advisory describes a use-after-free vulnerability in the Audio HAL component of MediaTek chipsets, which could allow a malicious actor with existing System privileges to escalate privileges locally without user interaction. The affected component is part of a chipset that could be deployed in automotive systems, but the advisory does not confirm such use. This could be relevant where MediaTek chipsets are deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
csaf_endresshauseragmedium Β· 6.7
vde-2026-065
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically the Endress+Hauser iDTM FDI package library used for device configuration and diagnostics. An attacker with elevated system access could enable a hidden debug interface by placing a crafted file, potentially gaining unauthorized remote control of connected process devices and disrupting or altering their data and operation. The risk is moderate and requires prior system access, but Endress+Hauser has released an updated library (V2.02.00) that fixes the issue, and restricting system access is strongly advised until patched.
csaf_siemensmedium Β· 6.7
ssa-288252
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically the IAM Client software used in Siemens automation products. An authenticated attacker with local access could exploit an unquoted search path to escalate their privileges, potentially gaining unauthorized control over manufacturing equipment or production line systems. Siemens has released updates for some affected products and recommends applying security patches and following industrial security guidelines to mitigate the risk.
cvelistv5medium Β· 6.6
cve-2026-11743
This vulnerability affects the SF32LB MPI QSPI NOR flash driver, which is a memory-mapped flash component used in embedded systems that could be deployed in automotive ECUs, telematics units, or infotainment modules. An attacker with access to the flash device could exploit a missing overflow check to read arbitrary memory contents or write to out-of-range flash addresses, potentially disclosing sensitive data or corrupting system integrity. The severity is high in configurations with userspace enabled, though it requires the flash device to be explicitly granted to an untrusted thread, and the fix involves adding proper bounds validation and DMA safeguards.