Anti-Theft Bypass for Infotainment ECU
Vulnerability Description
The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the head unit. It is possible to reveal all 32 corresponding responses by sniffing CAN traffic or by pre-calculating the values, which allow to bypass the protection. First identified on Nissan Leaf ZE1 manufactured in 2020.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-32056
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Polina Smirnova (PCA Cyber Security Assessment Team)
References
More from Bosch
View All →Affected Vendor
Bosch
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.