Impact
The vulnerability is a stack‑based buffer overflow located in the Bendix EC80 Brake ECU firmware. A crafted payload can crash the ECU and subsequently allow an attacker to execute arbitrary code or inject arbitrary CAN bus traffic. The impact includes loss of critical vehicle functions such as ABS, steering assist, speedometer, and shifting, which directly threatens safety and could lead to loss of vehicle control.
Affected Systems
Affected products are Bendix EC80ESP 2nd CAN, EC80ESP 4S/4M, EC80ESP 6S/6M, EC80ESP CAN Gateway, EC80ESP PLC, EC80ESP+ 2nd CAN, EC80ESP+ 6S/6M, EC80ESP+ Integrated TPMS, EC80ESP+ J1708, and EC80ESP+ PLC. Firmware updates specific to each model are required: for the EC80ESP+ family the latest release is Z300822; for the EC80ESP 6S/6M, PLC, 2nd CAN, and CAN Gateway the patch is Z302578; and for EC80ESP 4S/4M and PLC the patch is Z302579.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity when the flaw is exploited. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited in the wild. The exploit requires remote access to the CAN bus, which is typically limited to vehicle components or maintenance tools; however, if an attacker gains such access, the attack can be carried out from a distance, often without local presence. The absence of public exploitation evidence does not diminish the seriousness for users who have exposed CAN interfaces.
OpenCVE Enrichment