CVE-2017-9647

Description

A Stack-Based Buffer Overflow issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-2010, Ford a limited number of P-HEV vehicles, Infiniti 2013 JX35, Infiniti 2014-2016 QX60, Infiniti 2014-2016 QX60 Hybrid, Infiniti 2014-2015 QX50, Infiniti 2014-2015 QX50 Hybrid, Infiniti 2013 M37/M56, Infiniti 2014-2016 Q70, Infiniti 2014-2016 Q70L, Infiniti 2015-2016 Q70 Hybrid, Infiniti 2013 QX56, Infiniti 2014-2016 QX 80, and Nissan 2011-2015 Leaf. An attacker with a physical connection to the TCU may exploit a buffer overflow condition that exists in the processing of AT commands. This may allow arbitrary code execution on the baseband radio processor of the TCU.

Categories

6.6
CVSS
Severity: Medium
CVSS 3.0 •
CVSS 2.0 •
EPSS 0.10%
Third-Party Advisory securityfocus.com Third-Party Advisory us-cert.gov
Affected: n/a Continental AG Infineon S-Gold 2 (PMB 8876)
Published at:
Updated at:

References

Link Tags
http://www.securityfocus.com/bid/100132 vdb entry third party advisory
https://ics-cert.us-cert.gov/advisories/ICSA-17-208-01 third party advisory us government resource

Frequently Asked Questions

What is the severity of CVE-2017-9647?
CVE-2017-9647 has been scored as a medium severity vulnerability.
How to fix CVE-2017-9647?
To fix CVE-2017-9647, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2017-9647 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2017-9647 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2017-9647?
CVE-2017-9647 affects n/a Continental AG Infineon S-Gold 2 (PMB 8876).
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.