CVE-2023-34403 is a medium-severity vulnerability affecting Mercedes-Benz head-unit NTG6 systems, allowing an attacker with physical access to the Ethernet pins on the Base Board to gain access to the internal network. A race condition can then be exploited to spoof user data and access it via USB backup. The CVSS score is 4.9 (MEDIUM), indicating an attack vector requiring adjacent network access, low attack complexity, and low impacts on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2021CPE matchmatch criteria | cpe:2.3:a:mercedes-benz:headunit_ntg6_mercedes-benz_user_experience:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.