CVE-2023-28901
Last modified
CVE-2023-28901 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum speed, and other information of Skoda Connect service users by specifying an arbitrary vehicle VIN number.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum speed, and other information of Skoda Connect service users by specifying an arbitrary vehicle VIN number.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Skoda-Auto | Skoda Connect | All versions |
References
- https://asrg.io/security-advisories/cve-2023-28901/Third Party Advisory
- https://asrg.io/security-advisories/cve-2023-28901/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-28901?
How severe is CVE-2023-28901?
How do I fix CVE-2023-28901?
Are you affected by CVE-2023-28901?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
