CVE-2023-6073
Last modified
CVE-2023-6073 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls. . EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.
Metrics
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Volkswagen | Id.3 Firmware | < 3.2 |
References
- https://asrg.io/cve-2023-6073-dos-and-control-of-volume-settings-for-vw-id-3-icas3-ivi-ecu/Exploit, Third Party Advisory
- https://asrg.io/cve-2023-6073-dos-and-control-of-volume-settings-for-vw-id-3-icas3-ivi-ecu/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-6073?
How severe is CVE-2023-6073?
How do I fix CVE-2023-6073?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-6067The WP User Profile Avatar WordPress plugin through 1.0.1 do…5.4
- CVE-2023-6068On affected 7130 Series FPGA platforms running MOS and recen…3.1
- CVE-2023-6069Improper Link Resolution Before File Access in GitHub reposi…8.8
- CVE-2023-6070 A server-side request forgery vulnerability in ESM prior to…4.3
- CVE-2023-6071 An Improper Neutralization of Special Elements used in a co…7.2
- CVE-2023-6072 A cross-site scripting vulnerability in Trellix Central Man…5.4
- CVE-2023-6074A vulnerability was found in PHPGurukul Restaurant Table Boo…9.8
- CVE-2023-6075A vulnerability classified as problematic has been found in …6.1
- CVE-2023-6076A vulnerability classified as problematic was found in PHPGu…7.5
- CVE-2023-6077The Slider WordPress plugin before 3.5.12 does not ensure th…6.5
- CVE-2023-6078An OS Command Injection vulnerability exists in BIOVIA Mater…9.8
- CVE-2023-6079Rejected reason: appears to be a duplicate of CVE-2023-40206
Are you affected by CVE-2023-6073?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
