CVE-2020-16142: Low severity mercedes-benz comand vulnerability
On Mercedes-Benz C Class AMG Premium Plus c220 BlueTec vehicles, the Bluetooth stack mishandles %x and %c format-string specifiers in a device name in the COMAND infotainment software.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-16142.
What is the affected software in this vulnerability?
The affected software in this vulnerability is Mercedes-Benz COMAND infotainment software.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is low with a score of 3.5.
How does the Bluetooth stack mishandle format-string specifiers?
The Bluetooth stack mishandles %x and %c format-string specifiers in a device name in the COMAND infotainment software.
Is the Mercedes-benz C220 affected by this vulnerability?
No, the Mercedes-benz C220 is not affected by this vulnerability.
How can I fix this vulnerability?
There is currently no known fix for this vulnerability. It is recommended to follow any official instructions or patches provided by Mercedes-Benz.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following reference: [Medium - Mercedes COMAND Infotainment Improper Format Strings Handling](https://medium.com/@reliable_lait_mouse_975/mercedes-comand-infotainment-improper-format-strings-handling-4c67063d744e)