CISA

Bendix EC80 Brake ECU

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control.

The following versions of Bendix EC80 Brake ECU are affected:

EC80ESP+ J1708 Z228999

EC80ESP+ 6S/6M Z228999

EC80ESP+ PLC Z228999 

EC80ESP+ 2nd CAN Z228999

EC80ESP+ Integrated TPMS Z228999

EC80ESP 6S/6M Z266494 

EC80ESP PLC Z266494 

EC80ESP 2nd CAN Z266494

EC80ESP CAN Gateway Z266494 

EC80ESP 4S/4M Z286098 

EC80ESP PLC Z286098 

Vendor

Equipment

Bendix

Bendix EC80 Brake ECU

Stack-based Buffer Overflow, Out-of-bounds Write, Use of Hard-coded Credentials

Critical Infrastructure Sectors: Transportation Systems

Countries/Areas Deployed: United States, Canada

Company Headquarters Location: United States

The affected product is vulnerable to a stack-based buffer overflow, wh...