Mercedes-benz
Headunit Ntg6 Mercedes-benz User Experience: vulnerabilidades y CVE
Headunit Ntg6 Mercedes-benz User Experience tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-37603 | Media (4.6) | 0.33% | — | 13 feb 2025 | An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible type confusion exists in the user data import/export function of NTG 6 head units. To perform this attack, local access to the USB… |
| CVE-2024-37602 | Media (4.6) | 0.34% | — | 13 feb 2025 | An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible NULL pointer dereference in the Apple Car Play function affects NTG 6 head units. To perform this attack, physical… |
| CVE-2024-37601 | Media (4.6) | 0.34% | — | 13 feb 2025 | An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible heap buffer overflow exists in the user data import/export function of NTG 6 head units. To perform this attack, local access to the… |
| CVE-2024-37600 | Media (6.8) | 0.35% | — | 13 feb 2025 | An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible stack buffer overflow in the Service Broker service affects NTG 6 head units. To perform this attack, physical access… |
| CVE-2023-34406 | Baja (3.3) | 0.22% | — | 13 feb 2025 | An issue was discovered on Mercedes Benz NTG 6. A possible integer overflow exists in the user data import/export function of NTG (New Telematics Generation) 6 head units. To perform this attack, local access to USB… |
| CVE-2023-34404 | Media (4.9) | 0.44% | — | 13 feb 2025 | Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to these pins and get access to internal network. As a result, by accessing a specific port an attacker can send… |
| CVE-2023-34403 | Media (4.9) | 0.23% | — | 13 feb 2025 | Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to this pins and get access to internal network. A race condition can be acquired and attacker can spoof… |
| CVE-2023-34402 | Alta (7.7) | 0.22% | — | 13 feb 2025 | Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside file is encapsulate another file, which service will drop during processing. Due to missed checks, attacker can… |
| CVE-2023-34401 | Baja (3.7) | 0.29% | — | 13 feb 2025 | Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which is encoded with proprietary UD2 codec. Due to missed size checks in the… |
| CVE-2023-34400 | Alta (7.5) | 0.68% | — | 13 feb 2025 | Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. In case of parsing file, service try to define header inside the file and convert it to null-terminated string. If character… |
| CVE-2023-34399 | Crítica (9.8) | 0.83% | — | 13 feb 2025 | Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The version of boost library contains… |
| CVE-2023-34398 | Alta (7.5) | 0.68% | — | 13 feb 2025 | Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The boost library contains a vulnerability/null… |
| CVE-2023-34397 | Alta (7.5) | 0.64% | — | 13 feb 2025 | Mercedes Benz head-unit NTG 6 contains functions to import or export profile settings over USB. During parsing you can trigger that the service will be crashed. |
| CVE-2021-23908 | Crítica (9.8) | 2.4% | — | 13 may 2021 | An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A type confusion issue affects MultiSvSetAttributes in the HiQnet Protocol, leading to remote code… |
| CVE-2021-23907 | Crítica (9.8) | 2.4% | — | 13 may 2021 | An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The count in MultiSvGet, GetAttributes, and MultiSvSet is not checked in the HiQnet Protocol, leading… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.