#VU53385 Input validation error in MBUX Infotainment System - CVE-2021-23907
Published: May 20, 2021
MBUX Infotainment System
Mercedes-Benz
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists in the Headunit NTG6 on Mercedes-Benz vehicles due to the count in MultiSvGet, GetAttributes and MultiSvSet is not checked in the HiQnet Protocol. A remote attacker can pass specially crafted input and execute arbitrary code on the target system.