PT-2025-20889 · Bosch · Infotainment System Ecu

Mikhail Evdokimov

·

Published

2025-05-13

·

Updated

2026-02-15

·

CVE-2025-32060

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions versions prior to 2025-32060
Description The system lacks kernel module signature verification. An attacker gaining root access through other means can load custom kernel modules into the kernel space and execute code within the kernel context, potentially gaining full system control. This issue was initially identified on Nissan Leaf ZE1 vehicles manufactured in 2020.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2025-32060

Affected Products

Infotainment System Ecu