« Volver al listado

CVE-2018-18203

Estado: ModificadaMedia (6.4)—

Una vulnerabilidad en el mecanismo de actualización de Subaru StarLink Harman, en las unidades principales 2017, 2018 y 2019, podría otorgar a un atacante (con acceso físico a los puertos USB del vehículo) la capacidad de reescribir el firmware de la unidad principal. Esto ocurre debido a que el dispositivo acepta imágenes modificadas del sistema de archivos QNX6 (siempre que el atacante obtenga acceso a cierto código de descifrado/cifrado de Harman) como consecuencia de un error por el cual las imágenes no firmadas pasan una comprobación de validez. Un atacante podría instalar firmware de la unidad principal malicioso y persistente, así como ejecutar código arbitrario como usuario root.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-18203",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.4,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.5
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-11-28T23:29:00.357",
  "references": [
    {
      "url": "https://github.com/sgayou/subaru_starlink_research",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/sgayou/subaru_starlink_research",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in the update mechanism of Subaru StarLink Harman head units 2017, 2018, and 2019 may give an attacker (with physical access to the vehicle's USB ports) the ability to rewrite the firmware of the head unit. This occurs because the device accepts modified QNX6 filesystem images (as long as the attacker obtains access to certain Harman decryption/encryption code) as a consequence of a bug where unsigned images pass a validity check. An attacker could potentially install persistent malicious head unit firmware and execute arbitrary code as the root user."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en el mecanismo de actualización de Subaru StarLink Harman, en las unidades principales 2017, 2018 y 2019, podría otorgar a un atacante (con acceso físico a los puertos USB del vehículo) la capacidad de reescribir el firmware de la unidad principal. Esto ocurre debido a que el dispositivo acepta imágenes modificadas del sistema de archivos QNX6 (siempre que el atacante obtenga acceso a cierto código de descifrado/cifrado de Harman) como consecuencia de un error por el cual las imágenes no firmadas pasan una comprobación de validez. Un atacante podría instalar firmware de la unidad principal malicioso y persistente, así como ejecutar código arbitrario como usuario root."
    }
  ],
  "lastModified": "2026-06-17T01:46:50.697",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:subaru:starlink_2017_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F58AE13-21B3-4D68-BD6C-3DFB87C22EEC"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:subaru:starlink_2017:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AE566456-6FDF-46F2-A134-CF10F5A651A2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:subaru:starlink_2018_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F4A934A-77D5-458B-AEDF-DEAE4141D132"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:subaru:starlink_2018:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2C4D4E5F-2C65-4B74-95B5-7CB56A497B1B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:subaru:starlink_2019_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "84AE643D-BA28-4A9E-9F93-59016FC6D29B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:subaru:starlink_2019:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "10055215-2FA2-44F3-AC50-71654CA25353"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}