0.000
EPSS

CVE-2023-34402

CVSSv4: NA | CVSSv3: 7.7 | CVSSv2: NA | VMScore: 870 | EPSS: 0.00021 | KEV: Not Included
Published: 13/02/2025 Updated: 14/02/2025

Vulnerability Summary

Arbitrary File Write Vulnerability in Mercedes-Benz NTG6 Head-Unit via USB Profile Import

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside file is encapsulate another file, which service will drop during processing. Due to missed checks, attacker can achieve Arbitrary File Write with service speech rights.

Recent Articles

Mercedes-Benz Head Unit security research report
Securelist • Kaspersky Security Services • 17 Jan 2025

Introduction This report covers the research of the Mercedes-Benz Head Unit, which was made by our team. Mercedes-Benz’s latest Head Unit (infotainment system) is called Mercedes-Benz User Experience (MBUX). We performed analysis of the first generation MBUX. MBUX was previously analysed by KeenLab. Their report is a good starting point for diving deep into the MBUX internals and understanding the architecture of the system. In our research we performed detailed analysis of the first generatio...