PT-2024-12182 · Skoda · Skoda Vehicles

Abdellah Benotsmane

+1

·

Published

2024-01-12

·

Updated

2024-10-25

·

CVE-2023-28899

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Skoda vehicles (affected versions not specified)
Description The issue allows an attacker to send a specific reset UDS request via the OBDII port of Skoda vehicles, potentially causing the vehicle engine to shut down and resulting in the denial of service of other vehicle components, even when the vehicle is moving at a high speed. It is noted that no safety-critical functions are affected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2023-28899

Affected Products

Skoda Vehicles