Our takeCISA reports that vulnerabilities in the Bendix EC80 Brake ECU are confirmed exploited in the wild and can disable ABS, steering assist, speedometer, shifting, or traction control on affected models. Patch immediately if you run these units.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA reports active exploitation of multiple vulnerabilities in the Bendix EC80 Brake ECU (versions EC80ESP+ J1708 Z228999, EC80ESP+ 6S/6M Z228999, EC80ESP+ PLC Z228999, and EC80ESP+ 2nd CAN Z228999). If you operate commercial vehicles using these units, assess exposure immediately, apply any available mitigations or firmware updates, and monitor for loss of ABS, steering assist, speedometer, shifting, or traction control.
What this means for you — Lean IT orgs:If your fleet uses any of these exact Bendix EC80 Brake ECU versions, an attacker could disable critical safety systems like brakes and steering. Check your vehicles now and contact your mechanic or vendor for fixes.
What this means for you — MSP:Review client fleets and vehicle inventories for any of the four listed Bendix EC80 Brake ECU versions; these are confirmed exploited and can result in loss of ABS, steering assist, speedometer, shifting, or traction control. Prioritize remediation or isolation for affected assets.
What this means for you — Researcher:CISA reports active exploitation of vulnerabilities in Bendix EC80 Brake ECU (four specific ESP+ variants ending in Z228999). Successful exploitation can disable ABS, steering assist, speedometer, shifting, or automatic traction control.