6.8

CVE-2021-23906

Exploit

An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A Message Length is not checked in the HiQnet Protocol, leading to remote code execution.

Data is provided by the National Vulnerability Database (NVD)
Mercedes-benzMercedes-benz User Experience Version <= 2021
   Mercedes-benzA 220 Version-
   Mercedes-benzA 220 4matic Version-
   Mercedes-benzE 350 Version-
   Mercedes-benzE 350 4matic Version-
   Mercedes-benzEqc Version-
   Mercedes-benzGle 350 Version-
   Mercedes-benzGle 350 4matic Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.19% 0.405
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
cve@mitre.org 1.8 0.4 1.4
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.