Renault's vulnerability footprint centers on its electric vehicle platform, particularly the Zoe EV and its associated connectivity and firmware components, where the recurring weakness classes include authentication bypass via capture-replay attacks and improper handling of exceptional conditions. These findings reflect the embedded and wireless connectivity attack surface inherent to modern vehicle infotainment and battery-management systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Renault over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38766HIGH The remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same Rolling Codes set for each door-open request, which allows for a replay attack. | Jan 3, 2023 | 8.1 | 20 | NO | NO |
CVE-2023-39801MEDIUM A lack of exception handling in the Renault Easy Link Multimedia System Software Version 283C35519R allows attackers to cause a Denial of Service (DoS) via supplying crafted WMA fi | Aug 24, 2023 | 4.6 | 16 | NO | NO |
CVE-2023-39075MEDIUM Renault Zoe EV 2021 automotive infotainment system versions 283C35202R to 283C35519R (builds 11.10.2021 to 16.01.2023) allows attackers to crash the infotainment system by sending | Aug 3, 2023 | 4.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Renault.
Media articles that mention a CVE ID that affects a product developed by Renault — matched by CVE ID, not by vendor name.