Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.
References
Link | Resource |
---|---|
https://asrg.io/cve-2023-6073-dos-and-control-of-volume-settings-for-vw-id-3-icas3-ivi-ecu/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
18 Nov 2023, 03:21
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:volkswagen:id.3:-:*:*:*:*:*:*:* cpe:2.3:o:volkswagen:id.3_firmware:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.3 |
First Time |
Volkswagen
Volkswagen id.3 Volkswagen id.3 Firmware |
|
CWE | NVD-CWE-noinfo | |
References | () https://asrg.io/cve-2023-6073-dos-and-control-of-volume-settings-for-vw-id-3-icas3-ivi-ecu/ - Exploit, Third Party Advisory |
10 Nov 2023, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-10 08:15
Updated : 2023-11-18 03:21
NVD link : CVE-2023-6073
Mitre link : CVE-2023-6073
JSON object : View
Products Affected
volkswagen
- id.3
- id.3_firmware
CWE