PT-2021-15604 · Mercedes Benz · Mbux Infotainment System

Published

2021-05-13

·

Updated

2022-02-24

·

CVE-2021-23907

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Mercedes-Benz MBUX Infotainment System versions through 2021
Description: An issue in the Headunit NTG6 of the MBUX Infotainment System allows remote code execution due to the lack of count checks in the MultiSvGet, GetAttributes, and MultiSvSet functions within the HiQnet Protocol.
Recommendations: For versions through 2021, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-23907

Affected Products

Mbux Infotainment System