Vulnerabilities > KIA

DATE CVE VULNERABILITY TITLE RISK
2022-08-24 CVE-2022-37418 Authentication Bypass by Capture-replay vulnerability in multiple products
The Remote Keyless Entry (RKE) receiving unit on certain Nissan, Kia, and Hyundai vehicles through 2017 allows remote attackers to perform unlock operations and force a resynchronization after capturing two consecutive valid key fob signals over the radio, aka a RollBack attack.
high complexity
nissan kia hyundai CWE-294
6.4
2020-12-01 CVE-2020-8539 Incorrect Default Permissions vulnerability in KIA Head Unit Firmware Sop.003.30.18.0703/Sop.005.7.181019/Sop.007.1.191209
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon, to trigger unintended functionalities.
local
low complexity
kia CWE-276
7.8