Vulnerable Assets Library
A searchable database of maritime OT equipment with known vulnerabilities — covering navigation systems, engine automation, power management, and vessel control CBS from major marine vendors. Search by vendor, product family, or CVE ID to check whether equipment on your vessel has documented vulnerabilities requiring attention or patch management action.
Searchable by vendor
CVE referenced
Marine OT vendors
Continuously updated
Audit Level: Tactical
Records optimised: 30.06.2026 17:00 UTC
CVE-2018-18203 — Marine OT Device: n/a
Published: 2018-11-28 | Updated: 2024-08-05
N/A 0A vulnerability in the update mechanism of Subaru StarLink Harman head units 2017, 2018, and 2019 may give an attacker (with physical access to the vehicle's USB ports) the ability to rewrite the firmware of the head unit. This occurs because the device accepts modified QNX6 filesystem images (as long as the attacker obtains access to certain Harman decryption/encryption code) as a consequence of a bug where unsigned images pass a validity check. An attacker could potentially install persistent malicious head unit firmware and execute arbitrary code as the root user.
CVSS VECTOR: N/A
Get new CVE entries like these in your inbox weekly.
Subscribe →
Disclaimer & Methodology
The Marine OT Vulnerable Assets Library is a curated repository of security advisories identified through automated heuristic filtering. Users should verify hardware revisions with manufacturers before patching.
