ZeroHour

CVE-2023-28897

CVSS 3.1
9.8 critical
EPSS
<1%p24
Published
()
Modified
Description

The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulnerability discovered on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.

Vendors
skoda-auto
Products
superb 3 firmware
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.