On Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7 MMI Multiplayer with version (N+R_CN_AU_P0395) mishandles %x and %s format string specifiers in a device name. This may lead to memory content leaks and potentially crash the services.
References
| Link | Resource |
|---|---|
| https://tiger-team-1337.blogspot.com/2020/10/audi-a7-2014-mmi-mishandles-format.html | Exploit Third Party Advisory |
| https://twitter.com/Kevin2600/status/1316380576593571840 | Third Party Advisory |
| https://www.youtube.com/watch?v=BQUVgAdhwQs | Exploit Third Party Advisory |
| https://tiger-team-1337.blogspot.com/2020/10/audi-a7-2014-mmi-mishandles-format.html | Exploit Third Party Advisory |
| https://twitter.com/Kevin2600/status/1316380576593571840 | Third Party Advisory |
| https://www.youtube.com/watch?v=BQUVgAdhwQs | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
21 Nov 2024, 05:21
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://tiger-team-1337.blogspot.com/2020/10/audi-a7-2014-mmi-mishandles-format.html - Exploit, Third Party Advisory | |
| References | () https://twitter.com/Kevin2600/status/1316380576593571840 - Third Party Advisory | |
| References | () https://www.youtube.com/watch?v=BQUVgAdhwQs - Exploit, Third Party Advisory |
Information
Published : 2020-11-11 15:15
Updated : 2024-11-21 05:21
NVD link : CVE-2020-27524
Mitre link : CVE-2020-27524
CVE.ORG link : CVE-2020-27524
JSON object : View
Products Affected
audi
- mmi_multiplayer
- a7
CWE
CWE-134
Use of Externally-Controlled Format String
