PT-2025-1231 · Mercedes Benz · Mercedes-Benz Head-Unit Ntg6

Published

2025-01-17

·

Updated

2025-02-18

·

CVE-2023-34399

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mercedes-Benz head-unit NTG6 (affected versions not specified)
Description The issue is related to the import or export of profile settings over USB in the Mercedes-Benz head-unit NTG6. Some values are serialized using the boost library, which contains a vulnerability due to integer overflow. This vulnerability can be exploited to cause a denial of service. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00610
CVE-2023-34399

Affected Products

Mercedes-Benz Head-Unit Ntg6