Automotive Security Research Group (ASRG)

First CVE: Jun 1, 2023Active for: 3 years
88
CVEs Published
More CVEs Published than 68% of tracked CNAs
22.0
Avg CVEs / Year
More Avg CVEs / Year than 70% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Automotive Security Research Group (ASRG) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 1, 2023
3 years ago
Most Recent CVE
Jun 25, 2026
30 days ago

Top CVEs

All CVEs published by Automotive Security Research Group (ASRG) as a CNA, regardless of affected vendor or product.

88 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is
Feb 15, 20269.334NONO
Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on aff
Sep 23, 20246.831NOYES
The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary valid
Feb 15, 20268.830NONO
The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary valid
Feb 15, 20268.830NONO
The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary valid
Feb 15, 20268.830NONO
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to execute code on any Syrus4 device
Nov 21, 20239.830NONO
As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM to the clients. VTPM allows cl
Sep 21, 20239.930NONO
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, prima
Jun 13, 20259.429NONO
Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.
Nov 5, 20248.828NONO
Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of vehicles using the HopeChart HQT
Jun 1, 20239.828NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA88 CVEs
Severity distribution among all CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local20 (22.7%)
Network10 (11.4%)
Unknown0 (0.0%)
Physical21 (23.9%)
Adjacent Network32 (36.4%)
Attack Complexity
Low85 (96.6%)
High3 (3.4%)
Unknown0 (0.0%)
User Interaction
None77 (87.5%)
Unknown0 (0.0%)
Required11 (12.5%)
Privileges Required
Low18 (20.5%)
High6 (6.8%)
None64 (72.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (88 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.1% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Automotive Security Research Group (ASRG) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Automotive Security Research Group (ASRG) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs