Denial-of-Service
HARMAN Becker Automotive Systems GmbH
Mercedes Benz NTG 6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
5.5 medium
CVE-2023-34397
Head-unit NTG6 contains functions to import or export profile settings over USB. During parsing you can trigger that the service will be crashed.
Apply updates per vendor instructions.
Vulnerability was discovered by Radu Motspan (Kaspersky).
https://github.com/klsecservices/Advisories/blob/master/K-Mercedes-Benz-2023-002.md Report EN: https://securelist.com/mercedes-benz-head-unit-security-research/115218/ RU: https://securelist.ru/mercedes-benz-head-unit-security-research/111516/ https://github.com/klsecservices/Publications/blob/master/Mercedes-Benz_Head_Unit_security_research_report.pdf