Multiple flaws in Volkswagen Group's infotainment unit allow for vehicle compromise
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-28902 | An integer underflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause denial-of-service An integer underflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause denial-of-service of the infotainment system. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources. NVD description · AI analysis pending | 3.3 | <1% | — | — | ||
| CVE-2023-28903 | An integer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause a denial-of-servic An integer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause a denial-of-service of the infotainment system. NVD description · AI analysis pending | 3.3 | <1% | — | — | ||
| CVE-2023-28904 | A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to the MIB3 ECU A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to the MIB3 ECU to bypass firmware signature verification and run arbitrary code in the infotainment system at boot process. NVD description · AI analysis pending | 5.2 | <1% | — | — | ||
| CVE-2023-28905 | A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources. NVD description · AI analysis pending | 8.0 | <1% | — | — | ||
| CVE-2023-28906 | A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the system to escalate privileges and obtain adm A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the system to escalate privileges and obtain administrative access to the system. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources. NVD description · AI analysis pending | 7.8 | <1% | — | — | ||
| CVE-2023-28907 | There is no memory isolation between CPU cores of the MIB3 infotainment. There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to compromise the CPU core responsible for CAN message processing. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources. NVD description · AI analysis pending | 6.7 | <1% | — | — | ||
| CVE-2023-28911 +1 in the same advisory: …28908 | A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which can result in an arbitrary channel disconnection. An attacker can leverage this vulnerability to cause a denial-of-service attack for every connected client of the infotainment device. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources. NVD description · AI analysis pending | 6.5 group max | <1% | — | — | ||
| CVE-2023-28909 | A specific flaw exists within the Bluetooth stack of the MIB3 unit. A specific flaw exists within the Bluetooth stack of the MIB3 unit. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving fragmented HCI packets on a channel. An attacker can leverage this vulnerability to bypass the MTU check on a channel with enabled fragmentation. Consequently, this can lead to a buffer overflow in upper layer profiles, which can be used to obtain remote code execution. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources. NVD description · AI analysis pending | 8.0 | <1% | — | — | ||
| CVE-2023-28910 | A specific flaw exists within the Bluetooth stack of the MIB3 infotainment system. A specific flaw exists within the Bluetooth stack of the MIB3 infotainment system. The issue results from the disabled abortion flag eventually leading to bypassing assertion functions. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources. NVD description · AI analysis pending | 8.0 | <1% | — | — | ||
| CVE-2023-28912 | The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution privilege on the system or physical acce The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution privilege on the system or physical access to the system to obtain vehicle owner's contact data. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources. NVD description · AI analysis pending | 5.7 | <1% | — | — | ||
| CVE-2023-29113 | The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process communication m The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process communication mechanism, leaving attackers with presence in the system an ability to undermine access control restrictions implemented at the operating system level. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources. NVD description · AI analysis pending | 6.3 | <1% | — | — |
Full article474 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 16, 2024

Researchers discovered multiple flaws in the infotainment systems of Volkswagen Group vehicles that could allow to track them in real-time.
A team of security researchers from cybersecurity firm PCAutomotive discovered multiple vulnerabilities in the infotainment units used in some vehicles of the Volkswagen Group. Remote attackers can exploit the flaws to achieve certain controls and track the location of cars in real time.
The team led by Danila Parnishchev and Artem Ivachev discovered 12 vulnerabilities in the MIB3 infotainment systems, which appeared in 2021, and now being used in many VW Group cars.
Volkswagen Group does not manufacture its MIB3 infotainment systems but sources them from Tier-1 suppliers. Multiple versions exist, including models by Preh Car Connect GmbH, LG, and Aptiv. The experts focused on MIB3 units produced by Preh Car Connect GmbH.
The vulnerabilities recently disclosed impact the latest model of the Skoda Superb III sedan The experts presented the results of their research at the recent Black Hat Europe.
The recent study builds on earlier research that identified 21 vulnerabilities in Volkswagen vehicles in 2022, nine of which were disclosed in 2023.
The researchers identified an issue in the phone book synchronization process via Bluetooth, where the phone book consists of a sequence of vCards with a specific structure. They discovered a critical flaw in handling contact photos, where converting a photo associated with a contact could trigger a buffer overflow, potentially leading to arbitrary code execution.
An attacker could exploit the vulnerability to access the GPS data in real-time, access the contacts list, monitor speed, record in-car conversations, play sounds, and capture infotainment screenshots.
An unauthenticated attacker can exploit the issue within several meters of the target.

Below is the list of vulnerabilities discovered by the experts:
- CVE-2023-28902 DoS via integer underflow in picserver
- CVE-2023-28903 DoS via integer overflow in picserver
- CVE-2023-28904 Secure boot bypass in BL2
- CVE-2023-28905 Heap buffer overflow in picserver
- CVE-2023-28906 Command injection in networking service
- CVE-2023-28907 Lack of access restrictions in CARCOM memory
- CVE-2023-28908 Integer overflow in non-fragmented data (phone service)
- CVE-2023-28909 Integer overflow leading to MTU bypass (phone service)
- CVE-2023-28910 Disabled abortion flag (phone service)
- CVE-2023-28911 Arbitrary channel disconnection leading to DoS (phone service)
- CVE-2023-28912 Clear-text phonebook information
- CVE-2023-29113 Lack of access control in custom IPC mechanism
The researchers published a video PoC of attack exploiting the above flaws:
The Volkswagen Group confirmed that some issues have been already fixed and the others and are being addressed.
“The reported vulnerabilities in the infotainment system have been and are being addressed and eliminated through continuous improvement management via the lifecycle of our products. At no time was and is there any danger to the safety of our customers or our vehicles.” Skoda spokesperson told TechCrunch.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Volkswagen Group)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/172024/hacking/volkswagen-group-infotainment-unit-flaws.html