An issue was discovered in Mercedes Benz NTG (New...
Moderate severity
Unreviewed
Published
Feb 14, 2025
to the GitHub Advisory Database
•
Updated Feb 14, 2025
Description
Published by the National Vulnerability Database
Feb 13, 2025
Published to the GitHub Advisory Database
Feb 14, 2025
Last updated
Feb 14, 2025
An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible NULL pointer dereference in the Apple Car Play function affects NTG 6 head units. To perform this attack, physical access to Ethernet pins of the head unit base board is needed. With a static IP address, an attacker can connect via the internal network to the AirTunes / AirPlay service. With prepared HTTP requests, an attacker can cause the Car Play service to fail.
References