First published: Sun Nov 15 2020(Updated: )
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to device hardware to obtain system information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Harman Hermes | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19556 is a high-severity vulnerability that allows authentication bypass in the debug interface of the Mercedes-Benz HERMES 1 system.
To fix CVE-2019-19556, ensure that the affected version of the Harman Hermes software is updated to a patched version provided by the vendor.
CVE-2019-19556 affects users of Harman HERMES 1.0 who have physical access to the device hardware.
The implications of CVE-2019-19556 include the potential exposure of sensitive system information to attackers with physical access.
CVE-2019-19556 requires physical access to the device, making it primarily a local attack vulnerability rather than a remote one.