PT-2020-14773 · Mercedes Benz · Comand

Published

2020-08-27

·

Updated

2021-07-21

·

CVE-2020-16142

CVSS v2.0

2.9

Low

VectorAV:A/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Mercedes-Benz COMAND infotainment software (affected versions not specified)
Description The issue concerns the Bluetooth stack in the COMAND infotainment software, which fails to properly handle %x and %c format-string specifiers in a device name. This problem is specifically noted in Mercedes-Benz C Class AMG Premium Plus c220 BlueTec vehicles.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-16142

Affected Products

Comand