Stack-based Buffer Overflow in Bendix EC80 Brake ECU
Summary
| CVE | CVE-2026-67560 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-28 00:18:08 UTC |
| Updated | 2026-08-28 00:18:08 UTC |
| Description | Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting. |
Risk And Classification
Primary CVSS: v4.0 7.7 HIGH from [email protected]
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-121 | CWE-121 CWE-121
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 7.7 | HIGH | CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 7.7 | HIGH | CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Secondary | 7.5 | HIGH | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.5 | HIGH | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v4.0 Breakdown
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Bendix | EC80ESP J1708 | affected Z228999 | Not specified |
| CNA | Bendix | EC80ESP J1708 | unaffected Z300822 | Not specified |
| CNA | Bendix | EC80ESP 6S/6M | affected Z228999 | Not specified |
| CNA | Bendix | EC80ESP 6S/6M | unaffected Z300822 | Not specified |
| CNA | Bendix | EC80ESP PLC | affected Z228999 | Not specified |
| CNA | Bendix | EC80ESP PLC | unaffected Z300822 | Not specified |
| CNA | Bendix | EC80ESP 2nd CAN | affected Z228999 | Not specified |
| CNA | Bendix | EC80ESP 2nd CAN | unaffected Z300822 | Not specified |
| CNA | Bendix | EC80ESP Integrated TPMS | affected Z228999 | Not specified |
| CNA | Bendix | EC80ESP Integrated TPMS | unaffected Z300822 | Not specified |
| CNA | Bendix | EC80ESP 6S/6M | affected Z266494 | Not specified |
| CNA | Bendix | EC80ESP 6S/6M | unaffected Z302578 | Not specified |
| CNA | Bendix | EC80ESP PLC | affected Z266494 | Not specified |
| CNA | Bendix | EC80ESP PLC | unaffected Z302578 | Not specified |
| CNA | Bendix | EC80ESP 2nd CAN | affected Z266494 | Not specified |
| CNA | Bendix | EC80ESP 2nd CAN | unaffected Z302578 | Not specified |
| CNA | Bendix | EC80ESP CAN Gateway | affected Z266494 | Not specified |
| CNA | Bendix | EC80ESP CAN Gateway | unaffected Z302578 | Not specified |
| CNA | Bendix | EC80ESP 4S/4M | affected Z286098 | Not specified |
| CNA | Bendix | EC80ESP 4S/4M | unaffected Z302579 | Not specified |
| CNA | Bendix | EC80ESP PLC | affected Z286098 | Not specified |
| CNA | Bendix | EC80ESP PLC | unaffected Z302579 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/news-events/ics-advisories/icsa-26-237-05 | [email protected] | www.cisa.gov | |
| github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-23... | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Ben Gardiner of NMFTA reported this vulnerability to CISA. (en)
Additional Advisory Data
Solutions
CNA: Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at [email protected]. * EC80ESP+ J1708: Users should update their firmware to version Z300822. * EC80ESP+ 6S/6M: Users should update their firmware to version Z300822. * EC80ESP+ PLC: Users should update their firmware to version Z300822. * EC80ESP+ 2nd CAN: Users should update their firmware to version Z300822. * EC80ESP+ Integrated TPMS: Users should update their firmware to version Z300822. * EC80ESP 6S/6M: Users should update their firmware to version Z302578. * EC80ESP PLC: Users should update their firmware to version Z302578. * EC80ESP 2nd CAN: Users should update their firmware to version Z302578. * EC80ESP CAN Gateway: Users should update their firmware to version Z302578. * EC80ESP 4S/4M: Users should update their firmware to version Z302579. * EC80ESP PLC: Users should update their firmware to version Z302579.