PT-2025-1207 · Mercedes Benz · Mbux+1
Published
2025-01-17
·
Updated
2025-02-18
·
CVE-2024-37600
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mercedes Benz NTG (New Telematics Generation) versions 6 through 2021
Description
The issue is related to a possible stack buffer overflow in the Service Broker service of the Mercedes-Benz User Experience (MBUX) system, which can allow an attacker to execute arbitrary code or cause a denial of service. To exploit this issue, an attacker needs physical access to the Ethernet pins of the head unit base board and a static IP address to connect to the Service Broker service via the internal network. The attacker can then send prepared HTTP requests to cause the Service-Broker service to fail.
Recommendations
For Mercedes Benz NTG (New Telematics Generation) versions 6 through 2021, as a temporary workaround, consider restricting access to the Service Broker service until a patch is available. Additionally, ensure that physical access to the Ethernet pins of the head unit base board is secured to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mbux
Mercedes Benz Ntg