{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-67560",
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "state": "PUBLISHED",
        "assignerShortName": "icscert",
        "dateReserved": "2026-08-10T16:03:40.493Z",
        "datePublished": "2026-08-27T20:54:20.022Z",
        "dateUpdated": "2026-08-27T20:54:20.022Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
                "shortName": "icscert",
                "dateUpdated": "2026-08-27T20:54:20.022Z"
            },
            "title": "Stack-based Buffer Overflow in Bendix EC80 Brake ECU",
            "datePublic": "2026-08-25T14:28:00.000Z",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-121",
                            "description": "CWE-121",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Bendix",
                    "product": "EC80ESP+ J1708",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "Z228999"
                        },
                        {
                            "status": "unaffected",
                            "version": "Z300822"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Bendix",
                    "product": "EC80ESP+ 6S/6M",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "Z228999"
                        },
                        {
                            "status": "unaffected",
                            "version": "Z300822"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Bendix",
                    "product": "EC80ESP+ PLC",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "Z228999"
                        },
                        {
                            "status": "unaffected",
                            "version": "Z300822"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Bendix",
                    "product": "EC80ESP+ 2nd CAN",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "Z228999"
                        },
                        {
                            "status": "unaffected",
                            "version": "Z300822"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Bendix",
                    "product": "EC80ESP+ Integrated TPMS",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "Z228999"
                        },
                        {
                            "status": "unaffected",
                            "version": "Z300822"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Bendix",
                    "product": "EC80ESP 6S/6M",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "Z266494"
                        },
                        {
                            "status": "unaffected",
                            "version": "Z302578"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Bendix",
                    "product": "EC80ESP PLC",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "Z266494"
                        },
                        {
                            "status": "unaffected",
                            "version": "Z302578"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Bendix",
                    "product": "EC80ESP 2nd CAN",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "Z266494"
                        },
                        {
                            "status": "unaffected",
                            "version": "Z302578"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Bendix",
                    "product": "EC80ESP CAN Gateway",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "Z266494"
                        },
                        {
                            "status": "unaffected",
                            "version": "Z302578"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Bendix",
                    "product": "EC80ESP 4S/4M",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "Z286098"
                        },
                        {
                            "status": "unaffected",
                            "version": "Z302579"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Bendix",
                    "product": "EC80ESP PLC",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "Z286098"
                        },
                        {
                            "status": "unaffected",
                            "version": "Z302579"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Bendix EC80 Brake ECU\n is vulnerable to a stack-based buffer overflow, which may allow an \nattacker to crash the ECU. A crafted payload can then be used to \nremotely execute arbitrary code or inject arbitrary CAN bus traffic. \nThis could cause the loss of the ABS function, steering assist, \nspeedometer, and shifting.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Bendix EC80 Brake ECU\n is vulnerable to a stack-based buffer overflow, which may allow an \nattacker to crash the ECU. A crafted payload can then be used to \nremotely execute arbitrary code or inject arbitrary CAN bus traffic. \nThis could cause the loss of the ABS function, steering assist, \nspeedometer, and shifting."
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-05"
                },
                {
                    "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-05.json"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "ADJACENT_NETWORK",
                        "attackComplexity": "HIGH",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH",
                        "baseSeverity": "HIGH",
                        "baseScore": 7.5,
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
                    }
                },
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "ADJACENT",
                        "attackComplexity": "HIGH",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "HIGH",
                        "subConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "HIGH",
                        "subIntegrityImpact": "NONE",
                        "vulnAvailabilityImpact": "HIGH",
                        "subAvailabilityImpact": "NONE",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "HIGH",
                        "baseScore": 7.7,
                        "vectorString": "CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com.  *  EC80ESP+ J1708: Users should update their firmware to version Z300822.\n  *  EC80ESP+ 6S/6M: Users\n\n should update their firmware to version Z300822.\n  *  EC80ESP+ PLC: Users  should update their firmware to version Z300822.\n  *  EC80ESP+ 2nd CAN:\nUsers should update their firmware to version Z300822.\n  *  EC80ESP+ Integrated TPMS: Users should update their firmware to version Z300822.\n  *  EC80ESP 6S/6M:\nUsers\nshould update their firmware to version Z302578.\n  *  EC80ESP PLC:\nUsers\n\nshould update their firmware to version Z302578.\n  *  EC80ESP 2nd CAN:\nUsers\n\nshould update their firmware to version Z302578.\n  *  EC80ESP CAN Gateway:\nUsers\n\nshould update their firmware to version Z302578.\n  *  EC80ESP 4S/4M:\nUsers\n\nshould update their firmware to version Z302579.\n  *  EC80ESP PLC:\nUsers\n\nshould update their firmware to version Z302579.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com.<div><ul><li>EC80ESP+ J1708: Users should update their firmware to version Z300822.</li><li>EC80ESP+ 6S/6M:&nbsp;Users\n\n&nbsp;should update their firmware to version Z300822.</li><li>EC80ESP+ PLC:&nbsp;Users&nbsp;&nbsp;should update their firmware to version Z300822.</li><li>EC80ESP+ 2nd CAN:\nUsers&nbsp;should update their firmware to version Z300822.</li><li>EC80ESP+ Integrated TPMS:&nbsp;Users&nbsp;should update their firmware to version Z300822.</li><li>EC80ESP 6S/6M:\nUsers\nshould update their firmware to version Z302578.</li><li>EC80ESP PLC:\nUsers\n\nshould update their firmware to version Z302578.</li><li>EC80ESP 2nd CAN:\nUsers\n\nshould update their firmware to version Z302578.</li><li>EC80ESP CAN Gateway:\nUsers\n\nshould update their firmware to version Z302578.</li><li>EC80ESP 4S/4M:\nUsers\n\nshould update their firmware to version Z302579.</li><li>EC80ESP PLC:\nUsers\n\nshould update their firmware to version Z302579.</li></ul></div>"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Ben Gardiner of NMFTA reported this vulnerability to CISA.",
                    "type": "finder"
                }
            ],
            "source": {
                "advisory": "ICSA-26-237-05",
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.4"
            }
        }
    }
}