CVE-2018-9311
9.8
CRITICAL · CVSS 3.0 · EPSS 3.9% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a remote attack via a cellular network.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.86% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-693 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-05-31 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| bmw | telematics control unit |
| bmw | telematics control unit firmware |
References
- http://www.securityfocus.com/bid/104258
- https://keenlab.tencent.com/en/Experimental_Security_Assessment_of_BMW_Cars_by_KeenLab.pdf
- https://www.theregister.co.uk/2018/05/23/bmw_security_bugs/
- http://www.securityfocus.com/bid/104258
- https://keenlab.tencent.com/en/Experimental_Security_Assessment_of_BMW_Cars_by_KeenLab.pdf
- https://www.theregister.co.uk/2018/05/23/bmw_security_bugs/
→ the Explorer · watch your stack · NVD