is vulnerable to a stack-based buffer overflow, which may allow an
attacker to crash the ECU. A crafted payload can then be used to
remotely execute arbitrary code or inject arbitrary CAN bus traffic.
This could cause the loss of the ABS function, steering assist,
speedometer, and shifting.
Project Subscriptions
No advisories yet.
Solution
Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com. * EC80ESP+ J1708: Users should update their firmware to version Z300822. * EC80ESP+ 6S/6M: Users should update their firmware to version Z300822. * EC80ESP+ PLC: Users should update their firmware to version Z300822. * EC80ESP+ 2nd CAN: Users should update their firmware to version Z300822. * EC80ESP+ Integrated TPMS: Users should update their firmware to version Z300822. * EC80ESP 6S/6M: Users should update their firmware to version Z302578. * EC80ESP PLC: Users should update their firmware to version Z302578. * EC80ESP 2nd CAN: Users should update their firmware to version Z302578. * EC80ESP CAN Gateway: Users should update their firmware to version Z302578. * EC80ESP 4S/4M: Users should update their firmware to version Z302579. * EC80ESP PLC: Users should update their firmware to version Z302579.
Workaround
No workaround given by the vendor.
Fri, 28 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bendix
Bendix ec80esp+ 2nd Can Bendix ec80esp+ 6s/6m Bendix ec80esp+ Integrated Tpms Bendix ec80esp+ J1708 Bendix ec80esp+ Plc Bendix ec80esp 2nd Can Bendix ec80esp 4s/4m Bendix ec80esp 6s/6m Bendix ec80esp Can Gateway Bendix ec80esp Plc |
|
| Vendors & Products |
Bendix
Bendix ec80esp+ 2nd Can Bendix ec80esp+ 6s/6m Bendix ec80esp+ Integrated Tpms Bendix ec80esp+ J1708 Bendix ec80esp+ Plc Bendix ec80esp 2nd Can Bendix ec80esp 4s/4m Bendix ec80esp 6s/6m Bendix ec80esp Can Gateway Bendix ec80esp Plc |
Fri, 28 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting. | |
| Title | Stack-based Buffer Overflow in Bendix EC80 Brake ECU | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-28T14:13:53.473Z
Reserved: 2026-08-10T16:03:40.493Z
Link: CVE-2026-67560
Updated: 2026-08-28T14:06:07.043Z
Status : Received
Published: 2026-08-28T00:18:08.150
Modified: 2026-08-28T16:18:21.140
Link: CVE-2026-67560
No data.
OpenCVE Enrichment
Updated: 2026-08-28T16:13:47Z