CVE-2026-68967: Out-of-bounds Write in Bendix EC80 Brake ECU
Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bendix EC80 Brake ECU (EC80ESP EC80ESP+/variants)to a version that resolves this vulnerability.Fixed in Z300822 - Upgrade
Upgrade
Bendix EC80 Brake ECU (EC80ESP EC80ESP+/variants)to a version that resolves this vulnerability.Fixed in Z302578 - Upgrade
Upgrade
Bendix EC80 Brake ECU (EC80ESP EC80ESP+/variants)to a version that resolves this vulnerability.Fixed in Z302579
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates adjacent-network access is required. It does not require privileges or user interaction.
What is the expected security impact if exploitation succeeds?
The issue could give an attacker an arbitrary write primitive and could crash the ECU. The CVSS assessment rates integrity impact as high, with no confidentiality impact and no availability impact listed.