Vulnerability Description
Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-23
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-05
FAQ
What is CVE-2026-67560?
CVE-2026-67560 is a vulnerability with a CVSS score of 7.5 (HIGH). Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject a...
How severe is CVE-2026-67560?
CVE-2026-67560 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-67560?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.