CVE-2023-34403: Race Condition
Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to this pins and get access to internal network. A race condition can be acquired and attacker can spoof “UserData” with desirable file path and access it though backup on USB.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34403?
CVE-2023-34403 is considered a high severity vulnerability due to the potential for unauthorized access to internal networks.
How do I fix CVE-2023-34403?
To mitigate CVE-2023-34403, ensure that physical access to the Ethernet pins on the Mercedes-Benz head-unit NTG6 is restricted.
What type of attack does CVE-2023-34403 facilitate?
CVE-2023-34403 can facilitate an attack whereby an attacker connects to the Ethernet pins and exploits a race condition to access sensitive data.
Who is affected by CVE-2023-34403?
CVE-2023-34403 affects all users of the Mercedes-Benz head-unit NTG6 who have not implemented security measures to restrict physical access.
What can an attacker do with CVE-2023-34403?
An attacker exploiting CVE-2023-34403 can spoof 'UserData' to access files through USB backups on the affected head-unit.