VYPR

Superb III

by Skoda

CVEs (2)

  • CVE-2023-28906HigJun 28, 2025
    risk 0.51cvss 7.8epss 0.01

    A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the system to escalate privileges and obtain administrative access to the system. The vulnerability was originally discovered in Skoda Superb III car with MIB3…

  • CVE-2023-28896Dec 1, 2023
    risk 0.00cvss epss 0.00

    Access to critical Unified Diagnostics Services (UDS) of the Modular Infotainment Platform 3 (MIB3) infotainment is transmitted via Controller Area Network (CAN) bus in a form that can be easily decoded by attackers with physical access to the vehicle. Vulnerability discovered…