CVE-2023-28896

CVSS 3.1 Score 2.4 of 10 (low)

Details

Published Dec 1, 2023
Updated: Apr 24, 2024
CWE ID 326
CWE ID 261

Summary

CVE-2023-28896 is a vulnerability impacting the Unified Diagnostics Services (UDS) of the Modular Infotainment Platform 3 (MIB3) in Škoda Superb III (3V3) vehicles manufactured in 2022. The critical data transmitted via Controller Area Network (CAN) bus for accessing these services can be decoded by attackers with physical access to the vehicle, potentially leading to unauthorized control or manipulation of the infotainment system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share