Vulnerability Details CVE-2023-34403
Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to this pins and get access to internal network. A race condition can be acquired and attacker can spoof “UserData” with desirable file path and access it though backup on USB.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.8%
CVSS Severity
CVSS v3 Score 4.9
Products affected by CVE-2023-34403
-
cpe:2.3:a:mercedes-benz:headunit_ntg6_mercedes-benz_user_experience:2021