CVE-2021-23909: Critical severity mercedes-benz hermes vulnerability
Published May 13, 2021
·Updated
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The SH2 MCU allows remote code execution.
Affected Software
8 affected components
Mercedes-Benz HERMES=2.1
Mercedes-Benz A 220
Mercedes-Benz A 220 4matic
Mercedes-Benz E 350
Mercedes-Benz E 350 4matic
Mercedes-Benz Eqc
Mercedes-Benz Gle 350
Mercedes-Benz Gle 350 4matic
Event History
May 13, 2021
CVE Published
via MITRE·06:57 PM
Data Sourced
via MITRE·06:57 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2021-23909?
CVE-2021-23909 is a vulnerability discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles.
2
What is the severity of CVE-2021-23909?
CVE-2021-23909 has a severity rating of 9.8, which is considered critical.
3
What software versions are affected by CVE-2021-23909?
HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021 are affected by CVE-2021-23909.
4
How does CVE-2021-23909 allow remote code execution?
The SH2 MCU in HERMES 2.1 allows remote code execution, resulting in the vulnerability.
5
Is there a fix available for CVE-2021-23909?
It is recommended to refer to official advisories and updates from Mercedes-Benz for information on fixes for CVE-2021-23909.