PT-2025-29081 · Vw+3 · Vw+3
Published
2025-07-07
·
Updated
2025-10-02
·
CVE-2024-45431
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenSynergy BlueSDK (aka Blue SDK) versions through 6.x
Description:
The BlueSDK Bluetooth stack contains an Improper Input Validation flaw. The issue stems from insufficient validation of the remote L2CAP channel ID (CID). An attacker can exploit this to create an L2CAP channel using the null identifier as a remote CID. This chain of flaws allows for remote code execution via infotainment systems, confirmed in vehicles such as Mercedes-Benz, VW, and Skoda. Successful exploitation can grant access to GPS data, audio, and contacts, and potentially allow pivoting to core systems. It is estimated that millions of vehicles are impacted.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bluesdk
Mercedes-Benz
Skoda
Vw