← All CVEs

CVE-2023-34399

critical · 9.8

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The version of boost library contains vulnerability integer overflow.

9.8
CVSS
0.8%
EPSS (exploit prob.)
56th
EPSS percentile
2025-02-13
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-190

Affected products

VendorProductAffected versions
mercedes-benzheadunit_ntg6_mercedes-benz_user_experience<= 2021

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-34399