← Back to CVE List

CVE-2023-34401

Published: 2025-02-13T23:15Z
Last Modified: 2025-03-18T16:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which is encoded with proprietary UD2 codec. Due to missed size checks in the enapsulate file, attacker can achieve Out-of-Bound Read in heap memory. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt