Command Injection
HARMAN Becker Automotive Systems GmbH
Mercedes Benz NTG 6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
5.5 medium
CVE-2023-34404
Head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to these pins and get access to internal network. As a result, by accessing a specific port an attacker can send call request to all registered services in router and achieve command injection vulnerability.
Apply updates per vendor instructions.
Vulnerability was discovered by Radu Motspan (Kaspersky).
https://github.com/klsecservices/Advisories/blob/master/K-Mercedes-Benz-2023-009.md Report EN: https://securelist.com/mercedes-benz-head-unit-security-research/115218/ RU: https://securelist.ru/mercedes-benz-head-unit-security-research/111516/ https://github.com/klsecservices/Publications/blob/master/Mercedes-Benz_Head_Unit_security_research_report.pdf