CVE-2020-5551

HIGH

Toyota Display Control Unit - Unauthenticated Denial of Service and Arbitrary Command Execution via Bluetooth

Title source: llm
STIX 2.1

Description

Toyota 2017 Model Year DCU (Display Control Unit) allows an unauthenticated attacker within Bluetooth range to cause a denial of service attack and/or execute an arbitrary command. The affected DCUs are installed in Lexus (LC, LS, NX, RC, RC F), TOYOTA CAMRY, and TOYOTA SIENNA manufactured in the regions other than Japan from Oct. 2016 to Oct. 2019. An attacker with certain knowledge on the target vehicle control system may be able to send some diagnostic commands to ECUs with some limited availability impacts; the vendor states critical vehicle controls such as driving, turning, and stopping are not affected.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://jvn.jp/en/vu/JVNVU99396686/index.html
Exploit, Vendor Advisory x_refsource_misc
https://global.toyota/en/newsroom/corporate/32120629.html

Scores

CVSS v3 8.8
EPSS 0.0138
EPSS Percentile 68.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-276
Status published
Products (1)
toyota/display_control_unit
Published Mar 30, 2020
Tracked Since Feb 18, 2026