CVE-2026-67560
Awaiting Analysis Awaiting Analysis - Queue

Stack-Based Buffer Overflow in Bendix EC80 Brake ECU

Vulnerability report for CVE-2026-67560, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-03

Assigner: ICS-CERT

Description

Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-03
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
bendix ec80esp *
bendix ec80esp+ *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stack-based buffer overflow in the Bendix EC80 Brake ECU. It allows an attacker to send a crafted payload that crashes the ECU and may enable remote execution of arbitrary code or injection of malicious CAN bus traffic. This could lead to loss of critical vehicle functions like ABS, steering assist, speedometer, and shifting.

Detection Guidance

Detection requires checking firmware versions of Bendix EC80ESP and EC80ESP+ devices. Compare installed versions against recommended patched versions from Bendix. Monitor CAN bus traffic for unusual patterns or injected messages that may indicate exploitation attempts.

Impact Analysis

Exploitation could cause loss of ABS function, steering assist, speedometer, shifting, or disable automatic traction control. An attacker might remotely execute code or inject malicious traffic on the CAN bus, potentially compromising vehicle safety and control.

Compliance Impact

This vulnerability could lead to loss of critical vehicle functions like ABS, steering assist, and speedometer, which may impact safety and operational compliance with industry standards. However, the provided text does not specify direct effects on GDPR or HIPAA compliance.

Mitigation Strategies

Immediately update firmware to versions specified by Bendix for affected products (CSAFPID-0001 through CSAFPID-0011). Isolate ECUs from untrusted networks. Implement network monitoring for anomalous CAN bus activity. Disable unnecessary remote access until patches are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67560. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart