CVE-2024-37602: Null Pointer Dereference
An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible NULL pointer dereference in the Apple Car Play function affects NTG 6 head units. To perform this attack, physical access to Ethernet pins of the head unit base board is needed. With a static IP address, an attacker can connect via the internal network to the AirTunes / AirPlay service. With prepared HTTP requests, an attacker can cause the Car Play service to fail.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37602?
CVE-2024-37602 has been assessed as a medium severity vulnerability due to its requirement for physical access to exploit the NULL pointer dereference.
How do I fix CVE-2024-37602?
Fixing CVE-2024-37602 involves ensuring that access to the Ethernet pins of the NTG 6 head units is restricted to authorized personnel only.
What are the potential impacts of CVE-2024-37602?
The potential impact of CVE-2024-37602 includes causing a denial of service to the NTG 6 head unit by exploiting the NULL pointer dereference.
Is CVE-2024-37602 present in all versions of NTG 6?
CVE-2024-37602 affects Mercedes-Benz NTG 6 head units through the 2021 version.
Who is affected by CVE-2024-37602?
Owners of Mercedes-Benz vehicles equipped with the NTG 6 head unit up to the year 2021 are affected by CVE-2024-37602.