CVE-2023-28899

By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdown and denial of service of other vehicle components even when the vehicle is moving at a high speed. No safety critical functions affected. 
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:skoda-auto:superb_3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:skoda-auto:superb_3:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 4.7
References () https://asrg.io/security-advisories/cve-2023-28899 - Third Party Advisory () https://asrg.io/security-advisories/cve-2023-28899 - Third Party Advisory

25 Oct 2024, 21:35

Type Values Removed Values Added
CWE CWE-770

22 Jan 2024, 19:52

Type Values Removed Values Added
First Time Skoda-auto superb 3 Firmware
Skoda-auto
Skoda-auto superb 3
CPE cpe:2.3:o:skoda-auto:superb_3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:skoda-auto:superb_3:-:*:*:*:*:*:*:*
References () https://asrg.io/security-advisories/cve-2023-28899 - () https://asrg.io/security-advisories/cve-2023-28899 - Third Party Advisory
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

12 Jan 2024, 18:05

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-12 17:15

Updated : 2024-11-21 07:56


NVD link : CVE-2023-28899

Mitre link : CVE-2023-28899

CVE.ORG link : CVE-2023-28899


JSON object : View

Products Affected

skoda-auto

  • superb_3
  • superb_3_firmware
CWE
NVD-CWE-noinfo CWE-770

Allocation of Resources Without Limits or Throttling