Description

The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on behalf of root user (due to additional vulnerabilities), then he/she is also able to load custom kernel modules to the kernel space and execute code in the kernel context. Such a flaw can lead to taking control over the entire system. First identified on Nissan Leaf ZE1 manufactured in 2020.

INFO

Published Date :

2026-02-15T10:46:23.570Z

Last Modified :

2026-02-17T20:07:40.053Z

Source :

ASRG
AFFECTED PRODUCTS

The following products are affected by CVE-2025-32060 vulnerability.

Vendors Products
Bosch
  • Infotainment System Ecu

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact