// For flags

CVE-2018-18070

 

Severity Score

5.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in Daimler Mercedes-Benz COMAND 17/13.0 50.12 on Mercedes-Benz C-Class 2018 vehicles. Defining or receiving a specific navigation route might cause the system to freeze and reboot after a few transmissions. When the system next starts, it tries to re-calculate the route, which will cause a boot loop. (Under certain circumstances, it is possible to quickly overwrite the malicious route to regain the stability of the system.)

Se ha descubierto un problema en Daimler Mercedes-Benz COMAND 17/13.0 50.12 en vehículos Mercedes-Benz Clase C del 2018. Si se define o se recibe una ruta de navegación concreta, el sistema podría bloquearse y reiniciarse tras unas pocas transmisiones. Cuando el sistema arranca otra vez, intenta recalcular la ruta, lo que provocará un bucle de arranque. (En ciertas condiciones, es posible sobrescribir rápidamente la ruta maliciosa para recuperar la estabilidad del sistema).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-10-09 CVE Reserved
  • 2018-10-09 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
CAPEC
References (1)
URL Tag Source
https://vuldb.com/?id.125080 Third Party Advisory
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mercedes-benz
Search vendor "Mercedes-benz"
Comand
Search vendor "Mercedes-benz" for product "Comand"
17\/13.0_50.12
Search vendor "Mercedes-benz" for product "Comand" and version "17\/13.0_50.12"
-
Affected
in Mercedes-benz
Search vendor "Mercedes-benz"
C-class
Search vendor "Mercedes-benz" for product "C-class"
2018
Search vendor "Mercedes-benz" for product "C-class" and version "2018"
-
Safe