Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2023-47393

Disclosure Date: November 22, 2023 (last updated November 30, 2023)
An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the maintenance orders of other users and access sensitive user information via unspecified vectors.
Attacker Value
Unknown

CVE-2023-47392

Disclosure Date: November 22, 2023 (last updated November 30, 2023)
An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted add order request.
Attacker Value
Unknown

CVE-2023-23590

Disclosure Date: January 15, 2023 (last updated October 08, 2023)
Mercedes-Benz XENTRY Retail Data Storage 7.8.1 allows remote attackers to cause a denial of service (device restart) via an unauthenticated API request. The attacker must be on the same network as the device.
Attacker Value
Unknown

CVE-2021-23907

Disclosure Date: May 13, 2021 (last updated November 28, 2024)
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The count in MultiSvGet, GetAttributes, and MultiSvSet is not checked in the HiQnet Protocol, leading to remote code execution.
Attacker Value
Unknown

CVE-2021-23909

Disclosure Date: May 13, 2021 (last updated November 28, 2024)
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The SH2 MCU allows remote code execution.
Attacker Value
Unknown

CVE-2021-23908

Disclosure Date: May 13, 2021 (last updated November 28, 2024)
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A type confusion issue affects MultiSvSetAttributes in the HiQnet Protocol, leading to remote code execution.
Attacker Value
Unknown

CVE-2021-23910

Disclosure Date: May 13, 2021 (last updated November 28, 2024)
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. There is an out-of-bounds array access in RemoteDiagnosisApp.
Attacker Value
Unknown

CVE-2021-23906

Disclosure Date: May 13, 2021 (last updated November 28, 2024)
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A Message Length is not checked in the HiQnet Protocol, leading to remote code execution.
Attacker Value
Unknown

CVE-2020-16142

Disclosure Date: August 27, 2020 (last updated February 22, 2025)
On Mercedes-Benz C Class AMG Premium Plus c220 BlueTec vehicles, the Bluetooth stack mishandles %x and %c format-string specifiers in a device name in the COMAND infotainment software.
Attacker Value
Unknown

CVE-2018-18071

Disclosure Date: October 09, 2018 (last updated November 27, 2024)
An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data exchange between the app and a server might be intercepted. The app can be used to operate the Remote Parking Pilot, unlock the vehicle, or obtain sensitive information such as latitude, longitude, and direction of travel.
0