Mercedes-Benz XENTRY Retail Data Storage 7.8.1 allows remote attackers to cause a denial of service (device restart) via an unauthenticated API request. The attacker must be on the same network as the device.
References
Link | Resource |
---|---|
https://medium.com/@windsormoreira/xentry-retail-data-storage-v7-8-1-denial-of-service-cve-2023-23590-60b65f5fa358 | Exploit Third Party Advisory |
https://b2bconnect.mercedes-benz.com/gb/workshop-solutions/diagnosis/retail-data-storage | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2023-01-14 21:15
Updated : 2023-01-24 09:02
NVD link : CVE-2023-23590
Mitre link : CVE-2023-23590
JSON object : View
CWE
Products Affected
mercedes-benz
- xentry_retail_data_storage
- xentry_retail_data_storage_firmware