The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum speed, and other information of Skoda Connect service users by specifying an arbitrary vehicle VIN number.
References
Link | Resource |
---|---|
https://asrg.io/security-advisories/cve-2023-28901/ | Third Party Advisory |
https://asrg.io/security-advisories/cve-2023-28901/ | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-01-18 17:15
Updated : 2024-11-21 07:56
NVD link : CVE-2023-28901
Mitre link : CVE-2023-28901
CVE.ORG link : CVE-2023-28901
JSON object : View
Products Affected
skoda-auto
- skoda_connect
CWE