Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
cvelistv5medium Β· 4.7
cve-2026-76929
Wireshark versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 contain an out-of-bounds read vulnerability in the Pcapng file parser, which can cause a crash and lead to a denial of service when a malicious file is opened. This could be relevant where Wireshark is deployed in automotive systems for network analysis or diagnostics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 4.7
cve-2026-76927
A NULL pointer dereference vulnerability exists in the H.245 protocol dissector of Wireshark versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18, allowing a remote attacker to crash the application and cause a denial of service. This could be relevant where Wireshark is deployed in automotive systems for network analysis or diagnostics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 4.7
cve-2026-76920
Wireshark versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 contain an out-of-bounds write vulnerability in the 3GPP phone log file parser, which can cause a crash and lead to a denial of service. This could be relevant where Wireshark is deployed in automotive systems for network analysis or diagnostics, though the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 4.7
cve-2026-76889
The advisory describes a heap-based buffer overflow in the UMTS FP protocol dissector of Wireshark, affecting versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18, which can cause a crash and lead to denial of service. This could be relevant where Wireshark is deployed in automotive systems for network analysis or diagnostics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 4.7
cve-2026-76883
Wireshark versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 contain a heap-based buffer overflow in the Catapult DCT2000 file parser, which can crash the application and cause a denial of service. This could be relevant where Wireshark is deployed in automotive systems for network analysis or diagnostics, but the advisory does not confirm such use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 4.7
cve-2026-76882
Wireshark versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 contain an out-of-bounds read vulnerability in the Bluetooth Attribute Protocol dissector, which can cause a crash and lead to a denial of service when processing malformed packets. This could be relevant where Wireshark is deployed in automotive systems for network analysis or diagnostics, though the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 4.7
cve-2026-76881
A NULL pointer dereference vulnerability exists in Wireshark's CMS protocol dissector, affecting versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18. An attacker can exploit this to crash the application, resulting in a denial of service. This could be relevant where Wireshark is deployed in automotive systems for network analysis or diagnostics; confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 4.6
cve-2026-16148
The ITE it82xx2 USB device-controller driver in Zephyr can panic the kernel when a disable-then-enable cycle re-initializes a work item that is still pending, corrupting kernel internal lists. An attacker with a physically connected USB host can trigger this unauthenticated denial of service by forcing repeated attach, reset, or re-enumeration, with no confidentiality or integrity impact demonstrated. This could be relevant where the it82xx2 USB device controller is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 4.6
cve-2026-15923
A flaw in the Zephyr SDIO subsystem can cause a permanent hang when an SDIO card reports a maximum block size of zero, because the byte-I/O transfer loop never makes progress and never releases the card mutex. An attacker who can insert a crafted or malfunctioning removable SDIO/combo card could trigger this denial of service, which affects the SDIO peripheral and any dependent subsystem such as Wi-Fi until the device is reset; there is no memory-safety, confidentiality, or integrity impact, only availability loss. This could be relevant where Zephyr-based SDIO is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
csaf_nozominetworksmedium Β· 4.6
nn-2026:16-01
The advisory describes a template injection vulnerability in the Dashboards functionality of Guardian/CMC versions before 26.3.0, caused by improper validation of an input parameter. An attacker could exploit this insufficient sanitization to inject malicious templates, potentially leading to unauthorized actions or data exposure within the dashboard interface. The risk level for Nozomi customers is rated as Medium. This is relevant to automotive cybersecurity because Guardian/CMC is an operational technology security monitoring platform that could be deployed in automotive manufacturing or related industrial environments; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 4.6
cve-2026-12629
The advisory describes a denial-of-service vulnerability in the ARM PL011 UART driver within the Zephyr operating system. An attacker controlling a serial peer could inject line errors, causing an interrupt storm that permanently hangs the affected core, but only if an application explicitly enables error-interrupt reporting via a specific API. This could be relevant where the PL011 UART driver is deployed in automotive systems, such as in-vehicle communication or telematics modules. Confirm applicability through the product SBOM or dependency inventory.
fkie_nvdmedium Β· 4.5
cve-2026-8058
This vulnerability affects the OpenBMC firmware used in vehicle telematics and gateway modules for remote diagnostics and fleet management. An attacker with low-level access could supply a password in a resource dump request, which gets stored in plaintext in the audit log where an admin can see it, potentially exposing credentials. The severity is moderate, as it requires prior access but could lead to further system compromise.
cvelistv5medium Β· 4.4
cve-2026-20518
The advisory describes a vulnerability in MediaTek chipsets within the geniezone component, where a missing bounds check could allow local information disclosure. Exploitation requires that a malicious actor already has System privilege and that user interaction occurs. This could be relevant where MediaTek chipsets are deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 4.4
cve-2026-20514
This advisory describes a missing permission check in the MediaTek Audio HAL that could allow local information disclosure, but only if an attacker has already obtained System privilege, with no user interaction required. The affected component is part of a MediaTek chipset, which is not confirmed by the advisory to be in automotive products. This could be relevant where MediaTek chipsets are deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 4.4
cve-2026-20513
The advisory describes a vulnerability in the Audio HAL component of MediaTek chipsets, where improper input validation could allow local information disclosure. Exploitation requires an attacker to already have System privilege, and no user interaction is needed. This could be relevant where MediaTek chipsets are deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 4.3
cve-2026-42806
An out-of-bounds read vulnerability exists in the Bosch BME690 SensorAPI C-driver version v1.0.3 and prior, where the driver fails to validate a gas index value extracted from sensor data, allowing a read of up to 6 bytes past a stack buffer. An attacker or compromised peripheral on the I2C/SPI bus could supply a crafted payload with an out-of-range gas index, potentially corrupting measurements or leaking adjacent stack memory when data is logged or transmitted. This could be relevant where the BME690 sensor and its driver are deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 4.3
cve-2026-12630
Zephyr's 6LoWPAN IP Header Compression code contains an out-of-bounds read vulnerability in the destination addressing mode lookup, where an unauthenticated attacker on a nearby radio link can send a specially crafted frame to trigger a denial-of-service on the receiver. The affected component is Zephyr's networking stack for 802.15.4-based communication, which could be relevant where Zephyr is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
csaf_siemensmedium Β· 4.3
ssa-781903
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically Siemens Desigo DXR and PXC building automation controllers that manage HVAC and environmental systems in these facilities. An attacker on the network can send a single malformed BACnet packet to crash the controller, halting its ability to respond to commands until a manual reset or reboot is performed, which could disrupt factory climate control and potentially impact production operations. The severity is moderate but requires prompt patching, as Siemens has released updated firmware to fix the issue and recommends restricting network access to these devices.
fkie_nvdmedium Β· 4.3
cve-2026-13306
This vulnerability affects EV charging infrastructure including wallboxes, DC fast chargers, and charging station management systems. The flaw allows a physically present attacker to bypass authentication on the Autel MaxiCharger AC Elite Home charger by accessing its exposed USB interface without any credentials. This is a critical security issue because it could enable unauthorized control or manipulation of the charging system.
nvdmedium Β· 4.2
cve-2026-33957
Samsung Exynos 1580 firmware contains a flaw in its CustOS Driver where a request for oversized shared memory through the custos_iwc device can cause out-of-bounds read and write, potentially leading to memory corruption or information leakage. This could be relevant where the Exynos 1580 is deployed in automotive systems, though the advisory does not confirm an automotive connection. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 4.2
cve-2026-23791
Samsung Exynos mobile processors (models 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600) contain an out-of-bounds write in the DPU driver caused by missing input length validation during color mode LUT parsing, which can corrupt kernel memory and potentially allow privilege escalation. The advisory does not establish an automotive connection, but this could be relevant where these Exynos processors are deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-93204
A race condition in the Linux kernel's batman-adv distributed ARP table (DAT) code allows a parallel reader to observe a partially updated MAC address, potentially transmitting a corrupted address or poisoning the ARP cache. The fix stores the 48-bit MAC address in an atomic64_t so readers see either the old or new value, never a mix. The advisory does not state a severity rating. This could be relevant where the Linux kernel with batman-adv is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-93203
The Linux kernel's batman-adv mesh networking module contains a flaw in how it handles bridge loop avoidance claims, where parallel processing can corrupt the CRC bookkeeping so that a client's claim is recorded against the wrong backbone gateway. An attacker able to trigger this race could cause incorrect CRC state that is never recalculated, potentially disrupting traffic forwarding for affected clients. The advisory does not state a severity rating. This could be relevant where batman-adv is deployed in automotive systems, for example in vehicle-to-vehicle mesh or in-vehicle mesh networking. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-93202
The Linux kernel's I3C master subsystem contains a locking flaw where registering a newly discovered I3C device while holding a read lock can cause a recursive lock acquisition and deadlock, as the device probe may try to take the same lock again. An attacker able to trigger device registration, for example through driver bind or unbind operations, could cause the system to hang or become unresponsive. The advisory does not state a formal severity rating. This could be relevant where the Linux I3C master subsystem is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium
cve-2026-93199
A flaw in the Linux kernel's I3C master driver could cause the bus controller itself to be mistakenly identified as a duplicate I3C target device when searching for devices with the same identifier. The advisory does not state a specific attacker capability or severity rating, only that the fix excludes the controller from duplicate matching so the function returns only real duplicate targets. This could be relevant where the Linux I3C master driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.