PT-2018-18969 · Bmw · Hu Nbt
Published
2018-05-31
·
Updated
2018-06-29
·
CVE-2018-9312
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
BMW HU NBT (Infotainment) component on vehicles produced in 2012 through 2018
Description
The issue allows for a local attack when a USB device is plugged into the Head Unit HU NBT component.
Recommendations
For vehicles produced in 2012 through 2018, consider restricting access to the USB port to minimize the risk of exploitation until a fix is available.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hu Nbt