35
CVE-2023-34401
—CVSS 3.1
3.7 low
EPSS
<1%p21
Published
()
Modified
Description
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which is encoded with proprietary UD2 codec. Due to missed size checks in the enapsulate file, attacker can achieve Out-of-Bound Read in heap memory.
- Vendors
- mercedes-benz
- Products
- headunit ntg6 mercedes-benz user experience
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N