ID

VAR-201805-1010


CVE

CVE-2018-9312


TITLE

plural BMW In the series Head Unit HU_NBT Vulnerabilities related to failure of protection mechanisms in components

Trust: 0.8

sources: JVNDB: JVNDB-2018-005486

DESCRIPTION

The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 Series vehicles produced in 2012 through 2018 allows a local attack when a USB device is plugged in. plural BMW In the series Head Unit HU_NBT ( alias Infotainment) The component contains a vulnerability related to failure of the protection mechanism.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. HeadUnitHU_NBT (Infotainment) component is a system of infotainment systems. There are security holes in the HeadUnitHU_NBT component on several BMW cars (cars produced in 2012-2018). There are currently no detailed vulnerability descriptions. BMW Infotainment System Telematics/Control Unit/Central Gateway Module are prone to the following multiple security vulnerabilities: 1. A local code-execution vulnerability 2. A security-bypass vulnerability 3. A denial-of-service vulnerability 4. Multiple remote code-execution vulnerabilities An attacker can leverage these issues to execute arbitrary code with root privileges, bypass certain security restrictions, perform unauthorized actions, or gain sensitive information within the context of the affected system. Failed exploit attempts will likely result in denial of service conditions

Trust: 2.61

sources: NVD: CVE-2018-9312 // JVNDB: JVNDB-2018-005486 // CNVD: CNVD-2018-11271 // BID: 104258 // VULHUB: VHN-139344 // VULMON: CVE-2018-9312

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-11271

AFFECTED PRODUCTS

vendor:bmwmodel:head unit hu nbtscope:eqversion: -

Trust: 1.6

vendor:bmwmodel:head unit hu nbtscope: - version: -

Trust: 0.8

vendor:bayerischemodel:motoren werke ag bmw i seriesscope:gteversion:2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:x>=2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:3>=2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:5>=2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:7>=2012,<=2018

Trust: 0.6

vendor:bmwmodel:infotainment system telematicsscope:eqversion:0

Trust: 0.3

vendor:bmwmodel:control unitscope:eqversion:0

Trust: 0.3

vendor:bmwmodel:central gateway modulescope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2018-11271 // BID: 104258 // JVNDB: JVNDB-2018-005486 // CNNVD: CNNVD-201805-1155 // NVD: CVE-2018-9312

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-9312
value: HIGH

Trust: 1.0

NVD: CVE-2018-9312
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-11271
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201805-1155
value: HIGH

Trust: 0.6

VULHUB: VHN-139344
value: HIGH

Trust: 0.1

VULMON: CVE-2018-9312
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-9312
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2018-11271
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-139344
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-9312
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-11271 // VULHUB: VHN-139344 // VULMON: CVE-2018-9312 // JVNDB: JVNDB-2018-005486 // CNNVD: CNNVD-201805-1155 // NVD: CVE-2018-9312

PROBLEMTYPE DATA

problemtype:CWE-693

Trust: 1.9

sources: VULHUB: VHN-139344 // JVNDB: JVNDB-2018-005486 // NVD: CVE-2018-9312

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201805-1155

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-201805-1155

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-005486

PATCH

title:Top Pageurl:https://www.bmw.com/en/index.html

Trust: 0.8

title:The Registerurl:https://www.theregister.co.uk/2018/05/23/bmw_security_bugs/

Trust: 0.2

title:usb-device-securityurl:https://github.com/parallelbeings/usb-device-security

Trust: 0.1

sources: VULMON: CVE-2018-9312 // JVNDB: JVNDB-2018-005486

EXTERNAL IDS

db:NVDid:CVE-2018-9312

Trust: 3.5

db:BIDid:104258

Trust: 2.7

db:JVNDBid:JVNDB-2018-005486

Trust: 0.8

db:CNNVDid:CNNVD-201805-1155

Trust: 0.7

db:CNVDid:CNVD-2018-11271

Trust: 0.6

db:VULHUBid:VHN-139344

Trust: 0.1

db:VULMONid:CVE-2018-9312

Trust: 0.1

sources: CNVD: CNVD-2018-11271 // VULHUB: VHN-139344 // VULMON: CVE-2018-9312 // BID: 104258 // JVNDB: JVNDB-2018-005486 // CNNVD: CNNVD-201805-1155 // NVD: CVE-2018-9312

REFERENCES

url:https://www.theregister.co.uk/2018/05/23/bmw_security_bugs/

Trust: 2.6

url:http://www.securityfocus.com/bid/104258

Trust: 2.5

url:https://keenlab.tencent.com/en/experimental_security_assessment_of_bmw_cars_by_keenlab.pdf

Trust: 2.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-9312

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-9312

Trust: 0.8

url:https://www.bmw.com/en/index.html

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/693.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://github.com/parallelbeings/usb-device-security

Trust: 0.1

sources: CNVD: CNVD-2018-11271 // VULHUB: VHN-139344 // VULMON: CVE-2018-9312 // BID: 104258 // JVNDB: JVNDB-2018-005486 // CNNVD: CNNVD-201805-1155 // NVD: CVE-2018-9312

CREDITS

Keen Security Lab and Tencent.

Trust: 0.9

sources: BID: 104258 // CNNVD: CNNVD-201805-1155

SOURCES

db:CNVDid:CNVD-2018-11271
db:VULHUBid:VHN-139344
db:VULMONid:CVE-2018-9312
db:BIDid:104258
db:JVNDBid:JVNDB-2018-005486
db:CNNVDid:CNNVD-201805-1155
db:NVDid:CVE-2018-9312

LAST UPDATE DATE

2024-11-23T22:06:49.659000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-11271date:2018-06-12T00:00:00
db:VULHUBid:VHN-139344date:2018-06-29T00:00:00
db:VULMONid:CVE-2018-9312date:2018-06-29T00:00:00
db:BIDid:104258date:2018-05-22T00:00:00
db:JVNDBid:JVNDB-2018-005486date:2018-07-18T00:00:00
db:CNNVDid:CNNVD-201805-1155date:2020-07-24T00:00:00
db:NVDid:CVE-2018-9312date:2024-11-21T04:15:19.063

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-11271date:2018-06-12T00:00:00
db:VULHUBid:VHN-139344date:2018-05-31T00:00:00
db:VULMONid:CVE-2018-9312date:2018-05-31T00:00:00
db:BIDid:104258date:2018-05-22T00:00:00
db:JVNDBid:JVNDB-2018-005486date:2018-07-18T00:00:00
db:CNNVDid:CNNVD-201805-1155date:2018-06-01T00:00:00
db:NVDid:CVE-2018-9312date:2018-05-31T12:29:00.330