Vulnerabilities > CVE-2018-18070 - Infinite Loop vulnerability in Mercedes-Benz Comand 17/13.050.12

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
high complexity
mercedes-benz
CWE-835

Summary

An issue was discovered in Daimler Mercedes-Benz COMAND 17/13.0 50.12 on Mercedes-Benz C-Class 2018 vehicles. Defining or receiving a specific navigation route might cause the system to freeze and reboot after a few transmissions. When the system next starts, it tries to re-calculate the route, which will cause a boot loop. (Under certain circumstances, it is possible to quickly overwrite the malicious route to regain the stability of the system.)

Vulnerable Configurations

Part Description Count
OS
Mercedes-Benz
1
Hardware
Mercedes-Benz
1