2024-12-08 03:06:42 +00:00

64 lines
2.5 KiB
JSON

{
"id": "CVE-2024-39339",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-09-18T20:15:03.197",
"lastModified": "2024-11-06T20:35:19.170",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitive details such as diagnostic log traces, system logs, headunit passwords, and personally identifiable information (PII). The exposure of such information may have serious implications for user privacy and system integrity."
},
{
"lang": "es",
"value": "Se ha descubierto una vulnerabilidad en todas las versiones de las unidades centrales Smartplay, que se utilizan ampliamente en los autom\u00f3viles Suzuki y Toyota. Esta configuraci\u00f3n incorrecta puede provocar la divulgaci\u00f3n de informaci\u00f3n, filtrando detalles confidenciales como registros de diagn\u00f3stico, registros del sistema, contrase\u00f1as de la unidad central e informaci\u00f3n de identificaci\u00f3n personal (PII). La exposici\u00f3n de dicha informaci\u00f3n puede tener consecuencias graves para la privacidad del usuario y la integridad del sistema."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-922"
}
]
}
],
"references": [
{
"url": "https://docs.google.com/document/d/1S-d8zyZreYYGSIr4zGww6F2iBfD63v10Z3YVbGnp2es/edit?usp=sharing",
"source": "cve@mitre.org"
},
{
"url": "https://mohammedshine.github.io/CVE-2024-39339.html",
"source": "cve@mitre.org"
}
]
}