GM's vulnerability profile reflects its automotive and connected-vehicle portfolio, with observed issues clustering around its infotainment and telematics systems such as MyLink, OnStar, and vehicle platforms like the Chevrolet Equinox. The recurring weakness classes center on authentication, data handling, and information exposure—including improper authentication, cleartext storage of sensitive data, and exposure to unauthorized actors—typical of connected automotive systems where credential and sensor data protection is foundational.
The number and severity of CVEs published that impact products developed by Gm over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28885MEDIUM The MyLink infotainment system (build 2021.3.26) in General Motors Chevrolet Equinox 2021 vehicles allows attackers to cause a denial of service (temporary failure of Media Player | Mar 27, 2023 | 6.8 | 22 | NO | NO |
CVE-2017-9663HIGH An Cleartext Storage of Sensitive Information issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerabilit | Jan 9, 2018 | 7.5 | 22 | NO | NO |
CVE-2017-12695HIGH An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an atta | Jan 9, 2018 | 8.8 | 22 | NO | NO |
CVE-2017-12697MEDIUM A Man-in-the-Middle issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to | Jan 9, 2018 | 5.9 | 17 | NO | NO |
CVE-2023-39076MEDIUM Injecting random data into the USB memory area on a General Motors (GM) Chevrolet Equinox 2021 Software. 2021.03.26 (build version) vehicle causes a Denial of Service (DoS) in the | Sep 8, 2023 | 4.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gm.
Media articles that mention a CVE ID that affects a product developed by Gm — matched by CVE ID, not by vendor name.