CVE-2024-23928

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Jan 31, 2025
CWE ID 863

Summary

CVE-2024-23928 is a vulnerability affecting Pioneer DMH-WT7600NEX devices. It permits network-adjacent attackers to compromise the integrity of downloaded information without requiring authentication. The root cause is the inadequate validation of certificates in the telematics functionality operating over HTTPS. This issue can be exploited in conjunction with other vulnerabilities, potentially enabling an attacker to execute arbitrary code with root privileges.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share