PT-2023-27360 · Harman · Harman Infotainment

Published

2023-08-13

·

Updated

2023-08-21

·

CVE-2023-40292

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Harman Infotainment versions 20190525031613 and later
Description The issue discloses the IP address via CarPlay CTRL packets.
Recommendations For Harman Infotainment versions 20190525031613 and later, consider restricting access to CarPlay CTRL packets to minimize the risk of IP address disclosure until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2023-40292

Affected Products

Harman Infotainment