CVE-2017-9647 describes a stack-based buffer overflow in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset, impacting numerous BMW, Ford, Infiniti, and Nissan vehicle models from various years. An attacker with physical access to the Telematics Control Unit (TCU) can exploit this vulnerability by sending specially crafted AT commands, potentially leading to arbitrary code execution on the baseband radio processor. Rated 6.6 MEDIUM on CVSS, the attack requires physical access and low privileges, but can result in high impact to confidentiality, integrity, and availability. While there is no public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness despite no active exploitation in the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:infineon:s-gold_2_pmb_8876:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.