CVE-2020-27524
Severity CVSS v4.0:
Pending analysis
Type:
CWE-134
Format String Vulnerability
Publication date:
11/11/2020
Last modified:
30/12/2020
Description
On Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7 MMI Multiplayer with version (N+R_CN_AU_P0395) mishandles %x and %s format string specifiers in a device name. This may lead to memory content leaks and potentially crash the services.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Base Score 2.0
4.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:audi:mmi_multiplayer:n\+r_cn_au_p0395:*:*:*:*:*:*:* | ||
| cpe:2.3:h:audi:a7:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



