ID

VAR-201805-1011


CVE

CVE-2018-9313


TITLE

plural BMW In the series Head Unit HU_NBT Vulnerabilities related to failure of protection mechanisms in components

Trust: 0.8

sources: JVNDB: JVNDB-2018-005487

DESCRIPTION

The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 Series vehicles produced in 2012 through 2018 allows a remote attack via Bluetooth when in pairing mode, leading to a Head Unit reboot. plural BMW In the series Head Unit HU_NBT ( alias Infotainment) The component contains a vulnerability related to failure of the protection mechanism.Service operation interruption (DoS) There is a possibility of being put into a state. HeadUnitHU_NBT (Infotainment) component is a system of infotainment systems. There are security holes in the HeadUnitHU_NBT component on several BMW cars (cars produced in 2012-2018). A remote attacker can use this vulnerability to cause HeadUnit to restart with Bluetooth. BMW Infotainment System Telematics/Control Unit/Central Gateway Module are prone to the following multiple security vulnerabilities: 1. A local code-execution vulnerability 2. A security-bypass vulnerability 3. A denial-of-service vulnerability 4. Multiple remote code-execution vulnerabilities An attacker can leverage these issues to execute arbitrary code with root privileges, bypass certain security restrictions, perform unauthorized actions, or gain sensitive information within the context of the affected system. Failed exploit attempts will likely result in denial of service conditions

Trust: 2.61

sources: NVD: CVE-2018-9313 // JVNDB: JVNDB-2018-005487 // CNVD: CNVD-2018-11272 // BID: 104258 // VULHUB: VHN-139345 // VULMON: CVE-2018-9313

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-11272

AFFECTED PRODUCTS

vendor:bmwmodel:head unit hu nbtscope:eqversion: -

Trust: 1.6

vendor:bmwmodel:head unit hu nbtscope: - version: -

Trust: 0.8

vendor:bayerischemodel:motoren werke ag bmw i seriesscope:gteversion:2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:x>=2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:3>=2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:5>=2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:7>=2012,<=2018

Trust: 0.6

vendor:bmwmodel:infotainment system telematicsscope:eqversion:0

Trust: 0.3

vendor:bmwmodel:control unitscope:eqversion:0

Trust: 0.3

vendor:bmwmodel:central gateway modulescope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2018-11272 // BID: 104258 // JVNDB: JVNDB-2018-005487 // CNNVD: CNNVD-201805-1156 // NVD: CVE-2018-9313

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-9313
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-9313
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2018-11272
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201805-1156
value: MEDIUM

Trust: 0.6

VULHUB: VHN-139345
value: MEDIUM

Trust: 0.1

VULMON: CVE-2018-9313
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-9313
severity: MEDIUM
baseScore: 5.7
vectorString: AV:A/AC:M/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2018-11272
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-139345
severity: MEDIUM
baseScore: 5.7
vectorString: AV:A/AC:M/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-9313
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 1.6
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-11272 // VULHUB: VHN-139345 // VULMON: CVE-2018-9313 // JVNDB: JVNDB-2018-005487 // CNNVD: CNNVD-201805-1156 // NVD: CVE-2018-9313

PROBLEMTYPE DATA

problemtype:CWE-693

Trust: 1.9

sources: VULHUB: VHN-139345 // JVNDB: JVNDB-2018-005487 // NVD: CVE-2018-9313

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201805-1156

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201805-1156

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-005487

PATCH

title:Top Pageurl:https://www.bmw.com/en/index.html

Trust: 0.8

title:The Registerurl:https://www.theregister.co.uk/2018/05/23/bmw_security_bugs/

Trust: 0.2

sources: VULMON: CVE-2018-9313 // JVNDB: JVNDB-2018-005487

EXTERNAL IDS

db:NVDid:CVE-2018-9313

Trust: 3.5

db:BIDid:104258

Trust: 2.7

db:JVNDBid:JVNDB-2018-005487

Trust: 0.8

db:CNNVDid:CNNVD-201805-1156

Trust: 0.7

db:CNVDid:CNVD-2018-11272

Trust: 0.6

db:VULHUBid:VHN-139345

Trust: 0.1

db:VULMONid:CVE-2018-9313

Trust: 0.1

sources: CNVD: CNVD-2018-11272 // VULHUB: VHN-139345 // VULMON: CVE-2018-9313 // BID: 104258 // JVNDB: JVNDB-2018-005487 // CNNVD: CNNVD-201805-1156 // NVD: CVE-2018-9313

REFERENCES

url:https://www.theregister.co.uk/2018/05/23/bmw_security_bugs/

Trust: 2.7

url:http://www.securityfocus.com/bid/104258

Trust: 2.5

url:https://keenlab.tencent.com/en/experimental_security_assessment_of_bmw_cars_by_keenlab.pdf

Trust: 2.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-9313

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-9313

Trust: 0.8

url:https://www.bmw.com/en/index.html

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/693.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2018-11272 // VULHUB: VHN-139345 // VULMON: CVE-2018-9313 // BID: 104258 // JVNDB: JVNDB-2018-005487 // CNNVD: CNNVD-201805-1156 // NVD: CVE-2018-9313

CREDITS

Keen Security Lab and Tencent.

Trust: 0.9

sources: BID: 104258 // CNNVD: CNNVD-201805-1156

SOURCES

db:CNVDid:CNVD-2018-11272
db:VULHUBid:VHN-139345
db:VULMONid:CVE-2018-9313
db:BIDid:104258
db:JVNDBid:JVNDB-2018-005487
db:CNNVDid:CNNVD-201805-1156
db:NVDid:CVE-2018-9313

LAST UPDATE DATE

2024-11-23T22:06:49.582000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-11272date:2018-06-12T00:00:00
db:VULHUBid:VHN-139345date:2018-06-29T00:00:00
db:VULMONid:CVE-2018-9313date:2018-06-29T00:00:00
db:BIDid:104258date:2018-05-22T00:00:00
db:JVNDBid:JVNDB-2018-005487date:2018-07-18T00:00:00
db:CNNVDid:CNNVD-201805-1156date:2018-06-01T00:00:00
db:NVDid:CVE-2018-9313date:2024-11-21T04:15:19.210

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-11272date:2018-06-12T00:00:00
db:VULHUBid:VHN-139345date:2018-05-31T00:00:00
db:VULMONid:CVE-2018-9313date:2018-05-31T00:00:00
db:BIDid:104258date:2018-05-22T00:00:00
db:JVNDBid:JVNDB-2018-005487date:2018-07-18T00:00:00
db:CNNVDid:CNNVD-201805-1156date:2018-06-01T00:00:00
db:NVDid:CVE-2018-9313date:2018-05-31T12:29:00.393