CVE-2019-19557: Low severity harman hermes vulnerability
Published Nov 15, 2020
·Updated
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
Affected Software
1 affected component
Harman Hermes=1.0
Event History
Nov 15, 2020
CVE Published
via MITRE·11:49 PM
Data Sourced
via MITRE·11:49 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19557?
CVE-2019-19557 has a medium severity rating due to the requirement of physical access for exploitation.
2
What does CVE-2019-19557 affect?
CVE-2019-19557 affects the Harman Hermes software version 1.0.
3
How does CVE-2019-19557 exploit the system?
CVE-2019-19557 allows attackers with physical access to extract cellular modem information through a misconfigured debug interface.
4
Can CVE-2019-19557 be fixed?
Yes, CVE-2019-19557 can be resolved by properly securing the debug interface.
5
Who is impacted by CVE-2019-19557?
Users of vehicles equipped with the Harman Hermes system version 1.0 may be impacted by CVE-2019-19557.