Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-35gc-287r-3fpq

Опубликовано: 10 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.7

Описание

Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.

Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.

EPSS

Процентиль: 6%
0.00024
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.7
nvd
около 2 лет назад

Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.

EPSS

Процентиль: 6%
0.00024
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-20