ID

VAR-201805-1012


CVE

CVE-2018-9314


TITLE

plural BMW In the series Head Unit HU_NBT Vulnerabilities related to failure of protection mechanisms in components

Trust: 0.8

sources: JVNDB: JVNDB-2018-005488

DESCRIPTION

The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 Series vehicles produced in 2012 through 2018 allows an attack by an attacker who has direct physical access. plural BMW In the series Head Unit HU_NBT ( alias Infotainment) The component contains a vulnerability related to failure of the protection mechanism.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. HeadUnitHU_NBT (Infotainment) component is a system of infotainment systems. There are security holes in the HeadUnitHU_NBT component on several BMW cars (cars produced in 2012-2018). There are currently no detailed vulnerability descriptions. BMW Infotainment System Telematics/Control Unit/Central Gateway Module are prone to the following multiple security vulnerabilities: 1. A local code-execution vulnerability 2. A security-bypass vulnerability 3. A denial-of-service vulnerability 4. Multiple remote code-execution vulnerabilities An attacker can leverage these issues to execute arbitrary code with root privileges, bypass certain security restrictions, perform unauthorized actions, or gain sensitive information within the context of the affected system. Failed exploit attempts will likely result in denial of service conditions

Trust: 2.61

sources: NVD: CVE-2018-9314 // JVNDB: JVNDB-2018-005488 // CNVD: CNVD-2018-11273 // BID: 104258 // VULHUB: VHN-139346 // VULMON: CVE-2018-9314

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-11273

AFFECTED PRODUCTS

vendor:bmwmodel:head unit hu nbtscope:eqversion: -

Trust: 1.6

vendor:bmwmodel:head unit hu nbtscope: - version: -

Trust: 0.8

vendor:bayerischemodel:motoren werke ag bmw i seriesscope:gteversion:2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:x>=2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:3>=2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:5>=2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:7>=2012,<=2018

Trust: 0.6

vendor:bmwmodel:infotainment system telematicsscope:eqversion:0

Trust: 0.3

vendor:bmwmodel:control unitscope:eqversion:0

Trust: 0.3

vendor:bmwmodel:central gateway modulescope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2018-11273 // BID: 104258 // JVNDB: JVNDB-2018-005488 // CNNVD: CNNVD-201805-1157 // NVD: CVE-2018-9314

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-9314
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-9314
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2018-11273
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201805-1157
value: HIGH

Trust: 0.6

VULHUB: VHN-139346
value: HIGH

Trust: 0.1

VULMON: CVE-2018-9314
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-9314
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2018-11273
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-139346
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-9314
baseSeverity: MEDIUM
baseScore: 6.8
vectorString: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-11273 // VULHUB: VHN-139346 // VULMON: CVE-2018-9314 // JVNDB: JVNDB-2018-005488 // CNNVD: CNNVD-201805-1157 // NVD: CVE-2018-9314

PROBLEMTYPE DATA

problemtype:CWE-693

Trust: 1.9

sources: VULHUB: VHN-139346 // JVNDB: JVNDB-2018-005488 // NVD: CVE-2018-9314

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201805-1157

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-201805-1157

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-005488

PATCH

title:Top Pageurl:https://www.bmw.com/en/index.html

Trust: 0.8

title:The Registerurl:https://www.theregister.co.uk/2018/05/23/bmw_security_bugs/

Trust: 0.1

sources: VULMON: CVE-2018-9314 // JVNDB: JVNDB-2018-005488

EXTERNAL IDS

db:NVDid:CVE-2018-9314

Trust: 3.5

db:BIDid:104258

Trust: 2.7

db:JVNDBid:JVNDB-2018-005488

Trust: 0.8

db:CNNVDid:CNNVD-201805-1157

Trust: 0.7

db:CNVDid:CNVD-2018-11273

Trust: 0.6

db:VULHUBid:VHN-139346

Trust: 0.1

db:VULMONid:CVE-2018-9314

Trust: 0.1

sources: CNVD: CNVD-2018-11273 // VULHUB: VHN-139346 // VULMON: CVE-2018-9314 // BID: 104258 // JVNDB: JVNDB-2018-005488 // CNNVD: CNNVD-201805-1157 // NVD: CVE-2018-9314

REFERENCES

url:https://www.theregister.co.uk/2018/05/23/bmw_security_bugs/

Trust: 2.6

url:http://www.securityfocus.com/bid/104258

Trust: 2.4

url:https://keenlab.tencent.com/en/experimental_security_assessment_of_bmw_cars_by_keenlab.pdf

Trust: 2.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-9314

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-9314

Trust: 0.8

url:https://www.bmw.com/en/index.html

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/693.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/144331

Trust: 0.1

sources: CNVD: CNVD-2018-11273 // VULHUB: VHN-139346 // VULMON: CVE-2018-9314 // BID: 104258 // JVNDB: JVNDB-2018-005488 // CNNVD: CNNVD-201805-1157 // NVD: CVE-2018-9314

CREDITS

Keen Security Lab and Tencent.

Trust: 0.9

sources: BID: 104258 // CNNVD: CNNVD-201805-1157

SOURCES

db:CNVDid:CNVD-2018-11273
db:VULHUBid:VHN-139346
db:VULMONid:CVE-2018-9314
db:BIDid:104258
db:JVNDBid:JVNDB-2018-005488
db:CNNVDid:CNNVD-201805-1157
db:NVDid:CVE-2018-9314

LAST UPDATE DATE

2024-11-23T22:06:49.697000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-11273date:2018-06-12T00:00:00
db:VULHUBid:VHN-139346date:2018-06-29T00:00:00
db:VULMONid:CVE-2018-9314date:2018-06-29T00:00:00
db:BIDid:104258date:2018-05-22T00:00:00
db:JVNDBid:JVNDB-2018-005488date:2018-07-18T00:00:00
db:CNNVDid:CNNVD-201805-1157date:2020-07-24T00:00:00
db:NVDid:CVE-2018-9314date:2024-11-21T04:15:19.360

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-11273date:2018-06-12T00:00:00
db:VULHUBid:VHN-139346date:2018-05-31T00:00:00
db:VULMONid:CVE-2018-9314date:2018-05-31T00:00:00
db:BIDid:104258date:2018-05-22T00:00:00
db:JVNDBid:JVNDB-2018-005488date:2018-07-18T00:00:00
db:CNNVDid:CNNVD-201805-1157date:2018-06-01T00:00:00
db:NVDid:CVE-2018-9314date:2018-05-31T12:29:00.440