The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 Series vehicles produced in 2012 through 2018 allows local attacks involving the USB or OBD-II interface. An attacker can bypass the code-signing protection mechanism for firmware updates, and consequently obtain a root shell.
References
Link | Resource |
---|---|
https://www.theregister.co.uk/2018/05/23/bmw_security_bugs/ | Third Party Advisory |
https://keenlab.tencent.com/en/Experimental_Security_Assessment_of_BMW_Cars_by_KeenLab.pdf | Exploit Third Party Advisory |
http://www.securityfocus.com/bid/104258 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2018-05-31 05:29
Updated : 2018-06-29 11:53
NVD link : CVE-2018-9322
Mitre link : CVE-2018-9322
JSON object : View
CWE
CWE-693
Protection Mechanism Failure
Products Affected
bmw
- head_unit_hu_nbt_firmware
- head_unit_hu_nbt