CVE-2018-18070

MEDIUM

Mercedes-benz Comand - Infinite Loop

Title source: rule
STIX 2.1

Description

An issue was discovered in Daimler Mercedes-Benz COMAND 17/13.0 50.12 on Mercedes-Benz C-Class 2018 vehicles. Defining or receiving a specific navigation route might cause the system to freeze and reboot after a few transmissions. When the system next starts, it tries to re-calculate the route, which will cause a boot loop. (Under certain circumstances, it is possible to quickly overwrite the malicious route to regain the stability of the system.)

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://vuldb.com/?id.125080

Scores

CVSS v3 5.9
EPSS 0.0030
EPSS Percentile 52.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-835
Status published
Products (1)
mercedes-benz/comand 17\/13.0_50.12
Published Oct 09, 2018
Tracked Since Feb 18, 2026