LOW · 2.9

CVE-2021-23907

An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The count in MultiSvGet, GetAttributes, and MultiSvSet is not checked in the HiQnet...

Vulnerability Description

An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The count in MultiSvGet, GetAttributes, and MultiSvSet is not checked in the HiQnet Protocol, leading to remote code execution.

CVSS Score

2.9

LOW

CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
Mercedes-BenzHeadunit Ntg6 Mercedes-Benz User Experience2021
Mercedes-BenzA 220-
Mercedes-BenzA 220 4Matic-
Mercedes-BenzE 350-
Mercedes-BenzE 350 4Matic-
Mercedes-BenzEqc-
Mercedes-BenzGle 350-
Mercedes-BenzGle 350 4Matic-

References

FAQ

What is CVE-2021-23907?

CVE-2021-23907 is a vulnerability with a CVSS score of 2.9 (LOW). An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The count in MultiSvGet, GetAttributes, and MultiSvSet is not checked in the HiQnet...

How severe is CVE-2021-23907?

CVE-2021-23907 has been rated LOW with a CVSS base score of 2.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-23907?

Check the references section above for vendor advisories and patch information. Affected products include: Mercedes-Benz Headunit Ntg6 Mercedes-Benz User Experience, Mercedes-Benz A 220, Mercedes-Benz A 220 4Matic, Mercedes-Benz E 350, Mercedes-Benz E 350 4Matic.