CVE-2021-23908

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/05/2021
Last modified:
10/12/2021

Description

An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A type confusion issue affects MultiSvSetAttributes in the HiQnet Protocol, leading to remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mercedes-benz:headunit_ntg6_mercedes-benz_user_experience:2021:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:a_220:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:a_220_4matic:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:e_350:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:e_350_4matic:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:eqc:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:gle_350:-:*:*:*:*:*:*:*
cpe:2.3:h:mercedes-benz:gle_350_4matic:-:*:*:*:*:*:*:*