The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum speed, and other information of Skoda Connect service users by specifying an arbitrary vehicle VIN number.
References
Link | Resource |
---|---|
https://asrg.io/security-advisories/cve-2023-28901/ | Third Party Advisory |
https://asrg.io/security-advisories/cve-2023-28901/ | Third Party Advisory |
Configurations
History
21 Nov 2024, 07:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://asrg.io/security-advisories/cve-2023-28901/ - Third Party Advisory |
26 Jan 2024, 15:01
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CWE | NVD-CWE-noinfo | |
References | () https://asrg.io/security-advisories/cve-2023-28901/ - Third Party Advisory | |
CPE | cpe:2.3:a:skoda-auto:skoda_connect:-:*:*:*:*:*:*:* | |
First Time |
Skoda-auto skoda Connect
Skoda-auto |
18 Jan 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-18 17:15
Updated : 2024-11-21 07:56
NVD link : CVE-2023-28901
Mitre link : CVE-2023-28901
CVE.ORG link : CVE-2023-28901
JSON object : View
Products Affected
skoda-auto
- skoda_connect
CWE