ZeroHour

CVE-2023-6073

PoC
CVSS 3.1
6.3 medium
EPSS
<1%p33
Published
()
Modified
Description

Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.

Vendors
volkswagen
Products
id.3 firmware
Weakness
CWE-20, CWE-284
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

In the news

No ingested article mentions this CVE yet.