CVE-2021-23907: Critical severity mercedes-benz user experience vulnerability
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The count in MultiSvGet, GetAttributes, and MultiSvSet is not checked in the HiQnet Protocol, leading to remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-23907?
The severity of CVE-2021-23907 is critical with a severity value of 9.8.
How does CVE-2021-23907 affect Mercedes-Benz vehicles?
CVE-2021-23907 affects Mercedes-Benz vehicles with the Headunit NTG6 in the MBUX Infotainment System through 2021.
What is the HiQnet Protocol and how is it related to CVE-2021-23907?
The HiQnet Protocol is a protocol used in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles, and CVE-2021-23907 is a vulnerability in this protocol.
What is the impact of CVE-2021-23907?
CVE-2021-23907 allows remote code execution, which could lead to unauthorized access or control of the affected Mercedes-Benz vehicles.
How can CVE-2021-23907 be fixed?
To fix CVE-2021-23907, Mercedes-Benz vehicle owners should follow the recommendations provided by Mercedes-Benz, which may include updating the MBUX Infotainment System to a patched version or contacting a Mercedes-Benz authorized service center for assistance.