CVE-2024-37603

CVSS 3.1 Score 4.6 of 10 (medium)

Details

Published Feb 13, 2025
Updated: Feb 18, 2025
CWE ID 843

Summary

CVE-2024-37603 is a newly discovered vulnerability affecting Mercedes Benz NTG (New Telematics Generation) 6 head units. This issue involves a type confusion in the user data import/export function, which can be exploited when an attacker gains local access to the USB interface of the car. By providing specially crafted data, an attacker can cause the User-Data service to fail, leading to a service instance restart. This vulnerability could potentially disrupt the functionality of the car's telematics system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share