{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T15:46:07.222","vulnerabilities":[{"cve":{"id":"CVE-2025-32063","sourceIdentifier":"cve@asrg.io","published":"2026-02-15T11:15:54.443","lastModified":"2026-06-17T09:11:23.650","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens during the startup phase of a specific systemd service, and as a result, the following developer features will be activated: the disabled firewall and the launched SSH server.\n\n\n\nFirst identified on Nissan Leaf ZE1 manufactured in 2020."},{"lang":"es","value":"Hay una vulnerabilidad de configuración errónea dentro de la ECU de infoentretenimiento fabricada por BOSCH. La vulnerabilidad se produce durante la fase de inicio de un servicio systemd específico y, como resultado, se activarán las siguientes funciones de desarrollador: el cortafuegos deshabilitado y el servidor SSH iniciado.\n\nIdentificada por primera vez en el Nissan Leaf ZE1 fabricado en 2020."}],"affected":[{"source":"cve@asrg.io","affectedData":[{"vendor":"Bosch","product":"Infotainment system ECU","defaultStatus":"unaffected","platforms":["Linux"],"versions":[{"version":"283C30861E","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@asrg.io","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-17T16:43:14.113662Z","id":"CVE-2025-32063","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@asrg.io","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"http://i.blackhat.com/Asia-25/Asia-25-Evdokimov-Remote-Exploitation-of-Nissan-Leaf.pdf","source":"cve@asrg.io"},{"url":"https://pcacybersecurity.com/resources/advisory/vulnerabilities-in-nissan-infotainment-manufactured-by-bosch","source":"cve@asrg.io"},{"url":"https://www.nissan.co.uk/vehicles/new-vehicles/leaf.html","source":"cve@asrg.io"}]}}]}