ID

VAR-201805-1014


CVE

CVE-2018-9320


TITLE

plural BMW In the series Head Unit HU_NBT Vulnerabilities related to failure of protection mechanisms in components

Trust: 0.8

sources: JVNDB: JVNDB-2018-005490

DESCRIPTION

The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 Series vehicles produced in 2012 through 2018 allows a local attack when a USB device is plugged in. plural BMW In the series Head Unit HU_NBT ( alias Infotainment) The component contains a vulnerability related to failure of the protection mechanism.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. HeadUnitHU_NBT (Infotainment) component is a system of infotainment systems. There are security holes in the HeadUnitHU_NBT component on several BMW cars (cars produced in 2012-2018). There are currently no detailed vulnerability descriptions. BMW Infotainment System Telematics/Control Unit/Central Gateway Module are prone to the following multiple security vulnerabilities: 1. A local code-execution vulnerability 2. A security-bypass vulnerability 3. A denial-of-service vulnerability 4. Multiple remote code-execution vulnerabilities An attacker can leverage these issues to execute arbitrary code with root privileges, bypass certain security restrictions, perform unauthorized actions, or gain sensitive information within the context of the affected system. Failed exploit attempts will likely result in denial of service conditions

Trust: 2.61

sources: NVD: CVE-2018-9320 // JVNDB: JVNDB-2018-005490 // CNVD: CNVD-2018-11270 // BID: 104258 // VULHUB: VHN-139352 // VULMON: CVE-2018-9320

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-11270

AFFECTED PRODUCTS

vendor:bmwmodel:head unit hu nbtscope:eqversion: -

Trust: 1.6

vendor:bmwmodel:head unit hu nbtscope: - version: -

Trust: 0.8

vendor:bayerischemodel:motoren werke ag bmw i seriesscope:gteversion:2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:x>=2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:3>=2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:5>=2012,<=2018

Trust: 0.6

vendor:bayerischemodel:motoren werke ag bmw seriesscope:eqversion:7>=2012,<=2018

Trust: 0.6

vendor:bmwmodel:infotainment system telematicsscope:eqversion:0

Trust: 0.3

vendor:bmwmodel:control unitscope:eqversion:0

Trust: 0.3

vendor:bmwmodel:central gateway modulescope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2018-11270 // BID: 104258 // JVNDB: JVNDB-2018-005490 // CNNVD: CNNVD-201805-1154 // NVD: CVE-2018-9320

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-9320
value: HIGH

Trust: 1.0

NVD: CVE-2018-9320
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-11270
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201805-1154
value: HIGH

Trust: 0.6

VULHUB: VHN-139352
value: HIGH

Trust: 0.1

VULMON: CVE-2018-9320
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-9320
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2018-11270
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-139352
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-9320
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-11270 // VULHUB: VHN-139352 // VULMON: CVE-2018-9320 // JVNDB: JVNDB-2018-005490 // CNNVD: CNNVD-201805-1154 // NVD: CVE-2018-9320

PROBLEMTYPE DATA

problemtype:CWE-693

Trust: 1.9

sources: VULHUB: VHN-139352 // JVNDB: JVNDB-2018-005490 // NVD: CVE-2018-9320

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201805-1154

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-201805-1154

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-005490

PATCH

title:Top Pageurl:https://www.bmw.com/en/index.html

Trust: 0.8

title:The Registerurl:https://www.theregister.co.uk/2018/05/23/bmw_security_bugs/

Trust: 0.2

title:usb-device-securityurl:https://github.com/parallelbeings/usb-device-security

Trust: 0.1

sources: VULMON: CVE-2018-9320 // JVNDB: JVNDB-2018-005490

EXTERNAL IDS

db:NVDid:CVE-2018-9320

Trust: 3.5

db:BIDid:104258

Trust: 2.7

db:JVNDBid:JVNDB-2018-005490

Trust: 0.8

db:CNNVDid:CNNVD-201805-1154

Trust: 0.7

db:CNVDid:CNVD-2018-11270

Trust: 0.6

db:VULHUBid:VHN-139352

Trust: 0.1

db:VULMONid:CVE-2018-9320

Trust: 0.1

sources: CNVD: CNVD-2018-11270 // VULHUB: VHN-139352 // VULMON: CVE-2018-9320 // BID: 104258 // JVNDB: JVNDB-2018-005490 // CNNVD: CNNVD-201805-1154 // NVD: CVE-2018-9320

REFERENCES

url:https://www.theregister.co.uk/2018/05/23/bmw_security_bugs/

Trust: 2.6

url:http://www.securityfocus.com/bid/104258

Trust: 2.5

url:https://keenlab.tencent.com/en/experimental_security_assessment_of_bmw_cars_by_keenlab.pdf

Trust: 2.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-9320

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-9320

Trust: 0.8

url:https://www.bmw.com/en/index.html

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/693.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://github.com/parallelbeings/usb-device-security

Trust: 0.1

sources: CNVD: CNVD-2018-11270 // VULHUB: VHN-139352 // VULMON: CVE-2018-9320 // BID: 104258 // JVNDB: JVNDB-2018-005490 // CNNVD: CNNVD-201805-1154 // NVD: CVE-2018-9320

CREDITS

Keen Security Lab and Tencent.

Trust: 0.9

sources: BID: 104258 // CNNVD: CNNVD-201805-1154

SOURCES

db:CNVDid:CNVD-2018-11270
db:VULHUBid:VHN-139352
db:VULMONid:CVE-2018-9320
db:BIDid:104258
db:JVNDBid:JVNDB-2018-005490
db:CNNVDid:CNNVD-201805-1154
db:NVDid:CVE-2018-9320

LAST UPDATE DATE

2024-11-23T22:06:49.734000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-11270date:2018-06-12T00:00:00
db:VULHUBid:VHN-139352date:2018-06-29T00:00:00
db:VULMONid:CVE-2018-9320date:2018-06-29T00:00:00
db:BIDid:104258date:2018-05-22T00:00:00
db:JVNDBid:JVNDB-2018-005490date:2018-07-18T00:00:00
db:CNNVDid:CNNVD-201805-1154date:2020-07-24T00:00:00
db:NVDid:CVE-2018-9320date:2024-11-21T04:15:19.710

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-11270date:2018-06-12T00:00:00
db:VULHUBid:VHN-139352date:2018-05-31T00:00:00
db:VULMONid:CVE-2018-9320date:2018-05-31T00:00:00
db:BIDid:104258date:2018-05-22T00:00:00
db:JVNDBid:JVNDB-2018-005490date:2018-07-18T00:00:00
db:CNNVDid:CNNVD-201805-1154date:2018-06-01T00:00:00
db:NVDid:CVE-2018-9320date:2018-05-31T12:29:00.517