3.7
CVE-2023-34401
- EPSS 0.05%
- Veröffentlicht 13.02.2025 23:15:08
- Zuletzt bearbeitet 27.06.2025 16:12:44
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which is encoded with proprietary UD2 codec. Due to missed size checks in the enapsulate file, attacker can achieve Out-of-Bound Read in heap memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mercedes-benz ≫ Headunit Ntg6 Mercedes-benz User Experience Version <= 2021
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.165 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 3.7 | 1.2 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.