Vulnerability Details CVE-2023-28897
The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware.
Vulnerability discovered on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.4%
CVSS Severity
CVSS v3 Score 4.0
Products affected by CVE-2023-28897
-
cpe:2.3:h:skoda-auto:superb_3:-
-
cpe:2.3:o:skoda-auto:superb_3_firmware:2022