Vulnerability Description
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The SH2 MCU allows remote code execution.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mercedes-Benz | Hermes | 2.1 |
| Mercedes-Benz | A 220 | - |
| Mercedes-Benz | A 220 4Matic | - |
| Mercedes-Benz | E 350 | - |
| Mercedes-Benz | E 350 4Matic | - |
| Mercedes-Benz | Eqc | - |
| Mercedes-Benz | Gle 350 | - |
| Mercedes-Benz | Gle 350 4Matic | - |
Related Weaknesses (CWE)
References
- https://keenlab.tencent.com/en/2021/05/12/Tencent-Security-Keen-Lab-ExperimentalThird Party Advisory
- https://keenlab.tencent.com/en/whitepapers/Mercedes_Benz_Security_Research_ReporExploitThird Party Advisory
- https://media.daimler.com/marsMediaSite/en/instance/ko.xhtml?oid=49946866Third Party Advisory
- https://keenlab.tencent.com/en/2021/05/12/Tencent-Security-Keen-Lab-ExperimentalThird Party Advisory
- https://keenlab.tencent.com/en/whitepapers/Mercedes_Benz_Security_Research_ReporExploitThird Party Advisory
- https://media.daimler.com/marsMediaSite/en/instance/ko.xhtml?oid=49946866Third Party Advisory
FAQ
What is CVE-2021-23909?
CVE-2021-23909 is a vulnerability with a CVSS score of 6.3 (MEDIUM). An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The SH2 MCU allows remote code execution.
How severe is CVE-2021-23909?
CVE-2021-23909 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-23909?
Check the references section above for vendor advisories and patch information. Affected products include: Mercedes-Benz Hermes, Mercedes-Benz A 220, Mercedes-Benz A 220 4Matic, Mercedes-Benz E 350, Mercedes-Benz E 350 4Matic.