CVE-2021-23910: Critical severity mercedes-benz hermes vulnerability
Published May 13, 2021
·Updated
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. There is an out-of-bounds array access in RemoteDiagnosisApp.
Affected Software
8 affected components
Mercedes-Benz HERMES=2.1
Mercedes-Benz A 220
Mercedes-Benz A 220 4matic
Mercedes-Benz E 350
Mercedes-Benz E 350 4matic
Mercedes-Benz Eqc
Mercedes-Benz Gle 350
Mercedes-Benz Gle 350 4matic
Event History
May 13, 2021
CVE Published
via MITRE·06:57 PM
Data Sourced
via MITRE·06:57 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2021-23910?
CVE-2021-23910 is a vulnerability in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021, which allows for an out-of-bounds array access in RemoteDiagnosisApp.
2
What is the severity of CVE-2021-23910?
CVE-2021-23910 has a severity rating of 9.8 (Critical).
3
Which software versions are affected by CVE-2021-23910?
CVE-2021-23910 affects HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021.
4
How can I fix CVE-2021-23910?
To fix CVE-2021-23910, it is recommended to apply the latest security patches and updates provided by Mercedes-Benz.
5
Where can I find more information about CVE-2021-23910?
You can find more information about CVE-2021-23910 in the following references: [link1], [link2], [link3].