Описание
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A Message Length is not checked in the HiQnet Protocol, leading to remote code execution.
Ссылки
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2021 (включая)
Одновременно
cpe:2.3:a:mercedes-benz:mercedes-benz_user_experience:*:*:*:*:*:*:*:*
Одно из
cpe:2.3:h:mercedes-benz:a_220:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:a_220_4matic:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:e_350:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:e_350_4matic:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:eqc:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:gle_350:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:gle_350_4matic:-:*:*:*:*:*:*:*
EPSS
Процентиль: 48%
0.00251
Низкий
1.8 Low
CVSS3
6.8 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-20
Связанные уязвимости
github
больше 3 лет назад
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A Message Length is not checked in the HiQnet Protocol, leading to remote code execution.
EPSS
Процентиль: 48%
0.00251
Низкий
1.8 Low
CVSS3
6.8 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-20