CVE-2023-34402
Last modified
CVE-2023-34402 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside file is encapsulate another file, which service will drop during processing. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside file is encapsulate another file, which service will drop during processing. Due to missed checks, attacker can achieve Arbitrary File Write with service speech rights.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mercedes-Benz | Headunit Ntg6 Mercedes-Benz User Experience | <= 2021 |
References
- https://securelist.com/mercedes-benz-head-unit-security-research/115218/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-34402?
How severe is CVE-2023-34402?
How do I fix CVE-2023-34402?
Are you affected by CVE-2023-34402?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
