PT-2024-12184 · Skoda · Skoda Automotive Cloud
Anna Breeva
·
Published
2024-01-18
·
Updated
2024-01-26
·
CVE-2023-28901
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Skoda Automotive cloud (affected versions not specified)
Description
The Skoda Automotive cloud contains a Broken Access Control issue, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum speed, and other information of Skoda Connect service users by specifying an arbitrary vehicle VIN number.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Skoda Automotive Cloud