| CVE ID | CVSS Score | Severity | Description |
|---|---|---|---|
| CVE-2026-67560 | 7.5 | high |
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.
|
| CVE-2026-68967 | 6.5 | medium |
The affected product is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU.
|
| CVE-2026-71396 | 5.4 | medium |
The affected product uses hard-coded credentials, which could allow an attacker to disable automatic traction control.
|
| Vendor | Product | Asset Type | Purdue Level | Firmware |
|---|---|---|---|---|
| Bendix | Unknown | plc |
L1
|
Z266494 |
| Bendix | Unknown | plc |
L1
|
Z228999 |