Описание
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The count in MultiSvGet, GetAttributes, and MultiSvSet is not checked in the HiQnet Protocol, leading to remote code execution.
Ссылки
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:a:mercedes-benz:headunit_ntg6_mercedes-benz_user_experience:2021:*:*:*:*:*:*:*
Одно из
cpe:2.3:h:mercedes-benz:a_220:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:a_220_4matic:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:e_350:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:e_350_4matic:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:eqc:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:gle_350:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:gle_350_4matic:-:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.02019
Низкий
2.9 Low
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
github
больше 3 лет назад
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The count in MultiSvGet, GetAttributes, and MultiSvSet is not checked in the HiQnet Protocol, leading to remote code execution.
EPSS
Процентиль: 83%
0.02019
Низкий
2.9 Low
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
NVD-CWE-noinfo