Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker
to deliver a payload that could establish an arbitrary write primitive,
which could crash the ECU.

Project Subscriptions

Vendors Products
Ec80esp+ 2nd Can Subscribe
Ec80esp+ 6s/6m Subscribe
Ec80esp+ Integrated Tpms Subscribe
Ec80esp+ J1708 Subscribe
Ec80esp+ Plc Subscribe
Ec80esp 2nd Can Subscribe
Ec80esp 4s/4m Subscribe
Ec80esp 6s/6m Subscribe
Ec80esp Can Gateway Subscribe
Ec80esp Plc Subscribe
Advisories

No advisories yet.

Fixes

Solution

Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com. * EC80ESP+ J1708: Users should update their firmware to version Z300822. * EC80ESP+ 6S/6M: Users  should update their firmware to version Z300822. * EC80ESP+ PLC: Users  should update their firmware to version Z300822. * EC80ESP+ 2nd CAN: Users should update their firmware to version Z300822. * EC80ESP+ Integrated TPMS: Users should update their firmware to version Z300822. * EC80ESP 6S/6M: Users should update their firmware to version Z302578. * EC80ESP PLC: Users should update their firmware to version Z302578. * EC80ESP 2nd CAN: Users should update their firmware to version Z302578. * EC80ESP CAN Gateway: Users should update their firmware to version Z302578. * EC80ESP 4S/4M: Users should update their firmware to version Z302579. * EC80ESP PLC: Users should update their firmware to version Z302579.


Workaround

No workaround given by the vendor.

History

Fri, 28 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Bendix
Bendix ec80esp+ 2nd Can
Bendix ec80esp+ 6s/6m
Bendix ec80esp+ Integrated Tpms
Bendix ec80esp+ J1708
Bendix ec80esp+ Plc
Bendix ec80esp 2nd Can
Bendix ec80esp 4s/4m
Bendix ec80esp 6s/6m
Bendix ec80esp Can Gateway
Bendix ec80esp Plc
Vendors & Products Bendix
Bendix ec80esp+ 2nd Can
Bendix ec80esp+ 6s/6m
Bendix ec80esp+ Integrated Tpms
Bendix ec80esp+ J1708
Bendix ec80esp+ Plc
Bendix ec80esp 2nd Can
Bendix ec80esp 4s/4m
Bendix ec80esp 6s/6m
Bendix ec80esp Can Gateway
Bendix ec80esp Plc

Fri, 28 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU.
Title Out-of-bounds Write in Bendix EC80 Brake ECU
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-28T14:13:53.649Z

Reserved: 2026-08-10T16:03:40.497Z

Link: CVE-2026-68967

cve-icon Vulnrichment

Updated: 2026-08-28T14:06:14.631Z

cve-icon NVD

Status : Received

Published: 2026-08-28T00:18:08.480

Modified: 2026-08-28T16:18:21.303

Link: CVE-2026-68967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T16:13:49Z

Weaknesses