CVE-2024-37601: Buffer Overflow
An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible heap buffer overflow exists in the user data import/export function of NTG 6 head units. To perform this attack, local access to the USB interface of the car is needed. With prepared data, an attacker can cause the User-Data service to fail. The failed service instance will restart automatically.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37601?
The severity of CVE-2024-37601 is not explicitly rated but is classified as a potential heap buffer overflow vulnerability that requires local access to exploit.
How do I fix CVE-2024-37601?
To fix CVE-2024-37601, ensure that the NTG 6 software is updated to the latest version provided by Mercedes Benz.
What systems are affected by CVE-2024-37601?
CVE-2024-37601 affects the Mercedes Benz NTG 6 head units.
What type of vulnerability is CVE-2024-37601?
CVE-2024-37601 is identified as a heap buffer overflow vulnerability.
What access is required to exploit CVE-2024-37601?
Exploiting CVE-2024-37601 requires local access to the USB interface of the car.