CVE-2026-68967
Awaiting Analysis Awaiting Analysis - Queue

Out-of-Bounds Write in Bendix EC80 Brake ECU

Vulnerability report for CVE-2026-68967, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-03

Assigner: ICS-CERT

Description

Bendix EC80 Brake ECUΒ is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-03
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
bendix ec80esp *
bendix ec80esp+ *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, allowing an attacker to deliver a payload that could establish an arbitrary write primitive. This could crash the ECU and potentially lead to loss of brake system functionality.

Detection Guidance

Detection methods for this vulnerability are not explicitly detailed in the provided CVE data. However, monitoring for unusual CAN bus traffic or ECU behavior may help identify potential exploitation attempts.

Impact Analysis

An attacker could exploit this to crash the ECU, potentially disabling critical vehicle functions like the Anti-lock Braking System (ABS) or other brake-related controls, posing a safety risk.

Compliance Impact

The provided CVE data does not specify any direct impact on compliance with standards like GDPR or HIPAA. The vulnerability primarily affects the Bendix EC80 Brake ECU by allowing an out-of-bounds write, which could crash the ECU or establish an arbitrary write primitive. No information is given about data exposure, privacy violations, or regulatory compliance implications.

Mitigation Strategies

Update the firmware of Bendix EC80ESP and EC80ESP+ products to the latest versions recommended by Bendix to address the out-of-bounds write vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68967. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart