CVE-2023-34400 Details
Description
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. In case of parsing file, service try to define header inside the file and convert it to null-terminated string. If character is missed, will return null pointer.
A vulnerability exists in the Mercedes-Benz NTG6 head unit, specifically within the MBUX infotainment system, allowing for a denial-of-service condition. This issue arises when the head unit's 'UserData' service processes imported profile files from a USB device. The service decodes the files using a proprietary algorithm, but a flaw in the decoding process for certain binary files can cause a heap buffer overflow. This vulnerability was identified during research by Kaspersky and is triggered by the 'UserData' service when it imports profile data from USB storage, particularly files with the '.ud2' extension, which are processed by the head unit's voice recognition system.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://securelist.com/mercedes-benz-head-unit-security-research/115218/ | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mercedes-benz headunit ntg6 mercedes-benz user experience | <= 2021 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 27, 2025 | Initial Analysis | [email protected] |
| Mar 18, 2025 | CVE Modified | CISA-ADP |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Feb 14, 2025 | CVE Modified | CISA-ADP |
| Feb 13, 2025 | New CVE Received | [email protected] |