Impact
The vulnerability is a hard‑coded credential flaw in the Bendix EC80 Brake ECU that permits unauthorized authentication to the unit, enabling an attacker to disable automatic traction control. This disruption of a safety‑related function can reduce vehicle stability and increase the risk of an accident, representing a denial of critical vehicle controls. The weakness is identified as CWE‑798.
Affected Systems
Affected products include the Bendix EC80ESP 2nd CAN, 4S/4M, 6S/6M, CAN Gateway, PLC, and the EC80ESP+ variants (2nd CAN, 6S/6M, Integrated TPMS, J1708, PLC). Firmware updates required are Z302579 for the 4S/4M model, Z302578 for the 2nd CAN, 6S/6M, CAN Gateway and PLC units, and Z300822 for the EC80ESP+ family.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity vulnerability. The EPSS score is not available, so the current exploit probability is uncertain, and the vulnerability is not listed in the CISA KEV catalog. The attack vector likely requires access to the vehicle’s internal CAN or J1708 bus, either through physical penetration or a compromised on‑board system, to leverage the hard‑coded credentials and disable traction control. Given the danger to vehicle safety, the risk remains significant for environments where such access could be achieved.
OpenCVE Enrichment