SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2023-28904

A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to the MIB3 ECU to bypass firmware signature verification and run arbitrary code in the infotainment system…

MEDIUM 5.2EPSS 0.31%

Does this matter?

Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.

Description

A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to the MIB3 ECU to bypass firmware signature verification and run arbitrary code in the infotainment system at boot process.

CVSS 3.1
5.2 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
EPSS
0.31% probability · 23th percentile
CISA KEV
Not listed
Weakness
CWE-120
Source
cve@asrg.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.