PT-2025-27308 · Volkswagen · Mib3

Danila Parnishchev

+1

·

Published

2025-06-28

·

Updated

2025-06-30

·

CVE-2023-28904

CVSS v3.1

5.2

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions: MIB3 infotainment unit (affected versions not specified)
Description: A logic flaw in the bootloader component of the MIB3 infotainment unit leads to a RAM buffer overflow, allowing an attacker with physical access to the MIB3 ECU to bypass firmware signature verification and run arbitrary code in the infotainment system at boot process.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2023-28904

Affected Products

Mib3