First published: Mon Aug 07 2017(Updated: )
An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-2010, Ford a limited number of P-HEV vehicles, Infiniti 2013 JX35, Infiniti 2014-2016 QX60, Infiniti 2014-2016 QX60 Hybrid, Infiniti 2014-2015 QX50, Infiniti 2014-2015 QX50 Hybrid, Infiniti 2013 M37/M56, Infiniti 2014-2016 Q70, Infiniti 2014-2016 Q70L, Infiniti 2015-2016 Q70 Hybrid, Infiniti 2013 QX56, Infiniti 2014-2016 QX 80, and Nissan 2011-2015 Leaf. A vulnerability in the temporary mobile subscriber identity (TMSI) may allow an attacker to access and control memory. This may allow remote code execution on the baseband radio processor of the TCU.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Infineon S-gold 2 Pmb 8876 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9633 is classified as a high severity vulnerability due to its impact on vehicle electronics.
To mitigate CVE-2017-9633, it is recommended to apply firmware updates from the manufacturer that address the buffer overflow issues.
CVE-2017-9633 affects several car models including BMWs produced between 2009-2010, certain Ford P-HEV vehicles, and Infiniti models from 2013 to 2016.
CVE-2017-9633 is categorized as an Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability.
As of the latest reports, there is no evidence that CVE-2017-9633 is actively being exploited in the wild.