PT-2025-27310 · Volkswagen · Mib3

Artem Ivachev

+1

·

Published

2025-06-28

·

Updated

2025-07-03

·

CVE-2023-28906

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: MIB3 infotainment versions (affected versions not specified)
Description: A command injection in the networking service of the MIB3 infotainment allows an attacker already present in the system to escalate privileges and obtain administrative access to the system. The issue was originally discovered in a Skoda Superb III car with an MIB3 infotainment unit.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-28906

Affected Products

Mib3