Vulnerability Description
On Mercedes-Benz C Class AMG Premium Plus c220 BlueTec vehicles, the Bluetooth stack mishandles %x and %c format-string specifiers in a device name in the COMAND infotainment software.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mercedes-Benz | Comand | - |
| Mercedes-Benz | C220 | - |
Related Weaknesses (CWE)
References
- https://medium.com/%40reliable_lait_mouse_975/mercedes-comand-infotainment-impro
- https://medium.com/%40reliable_lait_mouse_975/mercedes-comand-infotainment-impro
FAQ
What is CVE-2020-16142?
CVE-2020-16142 is a vulnerability with a CVSS score of 3.5 (LOW). On Mercedes-Benz C Class AMG Premium Plus c220 BlueTec vehicles, the Bluetooth stack mishandles %x and %c format-string specifiers in a device name in the COMAND infotainment software.
How severe is CVE-2020-16142?
CVE-2020-16142 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-16142?
Check the references section above for vendor advisories and patch information. Affected products include: Mercedes-Benz Comand, Mercedes-Benz C220.