Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f52g-mqvx-jmjp

Опубликовано: 01 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 3.5

Описание

The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The console allows attackers with physical access to the MIB3 unit to gain full control over the PWC chip.

Vulnerability found on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.

The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The console allows attackers with physical access to the MIB3 unit to gain full control over the PWC chip.

Vulnerability found on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.

EPSS

Процентиль: 19%
0.00062
Низкий

3.5 Low

CVSS3

Дефекты

CWE-259
CWE-798

Связанные уязвимости

CVSS3: 3.5
nvd
около 2 лет назад

The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The console allows attackers with physical access to the MIB3 unit to gain full control over the PWC chip. Vulnerability found on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.

EPSS

Процентиль: 19%
0.00062
Низкий

3.5 Low

CVSS3

Дефекты

CWE-259
CWE-798