CVE-2021-23906: Input Validation
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A Message Length is not checked in the HiQnet Protocol, leading to remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23906?
CVE-2021-23906 is an issue discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021, which allows remote code execution.
How does CVE-2021-23906 affect Mercedes-Benz vehicles?
CVE-2021-23906 affects the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021 by not checking the message length in the HiQnet Protocol, leading to remote code execution.
What is the severity of CVE-2021-23906?
CVE-2021-23906 has a severity score of 6.8 (medium).
How can I fix CVE-2021-23906?
To fix CVE-2021-23906, it is recommended to apply the latest software update provided by Mercedes-Benz.
Where can I find more information about CVE-2021-23906?
You can find more information about CVE-2021-23906 in the references provided: https://keenlab.tencent.com/en/2021/05/12/Tencent-Security-Keen-Lab-Experimental-Security-Assessment-on-Mercedes-Benz-Cars/ and https://keenlab.tencent.com/en/whitepapers/Mercedes_Benz_Security_Research_Report_Final.pdf