Mercedes-Benz NTG6 Head Unit USB Profile Import Vulnerability Leading to Denial-of-Service

Vulnerability

A vulnerability exists in the Mercedes-Benz NTG6 head unit, specifically within the MBUX infotainment system, allowing for a denial-of-service condition. This issue arises when the head unit's 'UserData' service processes imported profile files from a USB device. The service decodes the files using a proprietary algorithm, but a flaw in the decoding process for certain binary files can cause a heap buffer overflow. This vulnerability was identified during research by Kaspersky and is triggered by the 'UserData' service when it imports profile data from USB storage, particularly files with the '.ud2' extension, which are processed by the head unit's voice recognition system.

Impact

Exploitation of this vulnerability causes the 'UserData' service to crash, freezing the system until the ECU is manually reset.

Reproduction

The vulnerability can be reproduced by exporting a user profile backup from the head unit to a USB drive, then importing the backup while the 'UserData' service is active. The imported files, especially those with the '.ud2' extension, will trigger the vulnerability by causing a heap buffer overflow, leading to a crash of the 'UserData' service.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
4.5
remediation
0.0
relevance
0.0
threat
4.8
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.