CVE-2023-34401

Publication date

2025-02-13 00:00:00

Family

mitre

State

PUBLISHED

Description

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which is encoded with proprietary UD2 codec. Due to missed size checks in the enapsulate file, attacker can achieve Out-of-Bound Read in heap memory.