CVE-2023-34404: Command Injection
Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to these pins and get access to internal network. As a result, by accessing a specific port an attacker can send call request to all registered services in router and achieve command injection vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34404?
CVE-2023-34404 is classified as a high-severity vulnerability due to potential command injection risks.
How do I fix CVE-2023-34404?
To mitigate CVE-2023-34404, users should ensure that the head-unit software is updated to the latest version provided by Mercedes-Benz.
What types of devices are affected by CVE-2023-34404?
CVE-2023-34404 affects the Mercedes-Benz NTG6 head-unit and associated modules.
How can an attacker exploit CVE-2023-34404?
An attacker can exploit CVE-2023-34404 by connecting to the Ethernet pins and sending malicious requests to the router services.
What are the consequences of CVE-2023-34404?
The consequences of CVE-2023-34404 include unauthorized access to internal networks and possible command injection, which can compromise device functionality.