VYPR

MIB3 infotainment

by Skoda

CVEs (3)

  • CVE-2023-29113MedJun 28, 2025
    risk 0.41cvss 6.3epss 0.00

    The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process communication mechanism, leaving attackers with presence in the system an ability to undermine access control restrictions implemented…

  • CVE-2023-28898MedJan 12, 2024
    risk 0.34cvss 5.3epss 0.00

    The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when the id parameter equals to zero. This issue allows an attacker connected to the in-vehicle Wi-Fi network to cause denial-of-service of the infotainment…

  • CVE-2023-28897MedJan 12, 2024
    risk 0.26cvss 4.0epss 0.00

    The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulnerability discovered on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.