CVE-2023-28905
Last modified
CVE-2023-28905 is a high-severity vulnerability rated 8/10 on the CVSS scale. A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-28905?
How severe is CVE-2023-28905?
How do I fix CVE-2023-28905?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-28899By sending a specific reset UDS request via OBDII port of Sk…5.5
- CVE-2023-28900The Skoda Automotive cloud contains a Broken Access Control …5.3
- CVE-2023-28901The Skoda Automotive cloud contains a Broken Access Control …5.3
- CVE-2023-28902An integer underflow in the image processing binary of the M…3.3
- CVE-2023-28903An integer overflow in the image processing binary of the MI…3.3
- CVE-2023-28904A logic flaw leading to a RAM buffer overflow in the bootloa…5.2
- CVE-2023-28906A command injection in the networking service of the MIB3 in…7.8
- CVE-2023-28907There is no memory isolation between CPU cores of the MIB3 i…6.7
- CVE-2023-28908A specific flaw exists within the Bluetooth stack of the MIB…5.4
- CVE-2023-28909A specific flaw exists within the Bluetooth stack of the MIB…8
- CVE-2023-2891The WP EasyCart plugin for WordPress is vulnerable to Cross-…4.3
- CVE-2023-28910A specific flaw exists within the Bluetooth stack of the MIB…8
Are you affected by CVE-2023-28905?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
