cvedb.io
CVE-2024-8359
MEDIUM · CVSS 6.8
EPSS exploitation probability: 0%
Published 2024-11-22T22:15:19.373 · Last modified 2026-06-17T08:22:25.830

Summary

Visteon Infotainment REFLASH_DDU_FindFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit this vulnerability. The specific flaw exists within the REFLASH_DDU_FindFile function. A crafted software update file can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23420.

Affected products

visteon — infotainment

Does this affect you?

Add your gear to cvedb and we'll alert you only when visteon ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.