PT-2023-22035 · Volkswagen · Mib3
Danila Parnishchev
·
Publicado
2023-12-01
·
Atualizado
2023-12-30
·
CVE-2023-28895
CVSS v3.1
6.8
Média
| Vetor | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MIB3 infotainment (affected versions not specified)
Description
The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. This allows attackers with physical access to the MIB3 unit to gain full control over the PWC chip. The issue was found on the Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mib3