CVE-2023-34398: Null Pointer Dereference
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The boost library contains a vulnerability/null pointer dereference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34398?
CVE-2023-34398 is classified as a vulnerability that can potentially lead to a null pointer dereference.
How do I fix CVE-2023-34398?
To address CVE-2023-34398, ensure that your Mercedes-Benz NTG6 system is updated with the latest firmware that mitigates this vulnerability.
What systems are affected by CVE-2023-34398?
CVE-2023-34398 affects the Mercedes-Benz NTG6 head unit and the Boost library used within it.
What impact does CVE-2023-34398 have on the user?
CVE-2023-34398 may lead to crashes or unintended behaviors in the Mercedes-Benz NTG6 head unit due to the null pointer dereference.
Is my vehicle at risk due to CVE-2023-34398?
If your vehicle uses the Mercedes-Benz NTG6 head unit and is relying on the vulnerable Boost library, it may be at risk.