Описание
Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.2 (исключая)
Одновременно
cpe:2.3:o:volkswagen:id.3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:volkswagen:id.3:-:*:*:*:*:*:*:*
EPSS
Процентиль: 6%
0.00024
Низкий
5.7 Medium
CVSS3
6.3 Medium
CVSS3
Дефекты
CWE-20
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 5.7
github
около 2 лет назад
Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.
EPSS
Процентиль: 6%
0.00024
Низкий
5.7 Medium
CVSS3
6.3 Medium
CVSS3
Дефекты
CWE-20
NVD-CWE-noinfo