Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-28895

Опубликовано: 01 дек. 2023
Источник: nvd
CVSS3: 3.5
CVSS3: 6.8
EPSS Низкий

Описание

The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The console allows attackers with physical access to the MIB3 unit to gain full control over the PWC chip.

Vulnerability found on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:preh:mib3_firmware:*:*:*:*:*:*:*:*
Версия до 0304 (исключая)
cpe:2.3:h:preh:mib3:-:*:*:*:*:*:*:*

EPSS

Процентиль: 19%
0.00062
Низкий

3.5 Low

CVSS3

6.8 Medium

CVSS3

Дефекты

CWE-259
CWE-798

Связанные уязвимости

CVSS3: 3.5
github
около 2 лет назад

The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The console allows attackers with physical access to the MIB3 unit to gain full control over the PWC chip. Vulnerability found on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.

EPSS

Процентиль: 19%
0.00062
Низкий

3.5 Low

CVSS3

6.8 Medium

CVSS3

Дефекты

CWE-259
CWE-798