SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2023-28906

A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the system to escalate privileges and obtain administrative access to the system.

HIGH 7.8EPSS 0.66%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the system to escalate privileges and obtain administrative access to the system. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.66% probability · 49th percentile
CISA KEV
Not listed
Weakness
CWE-78
Source
cve@asrg.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.