A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to the MIB3 ECU to bypass firmware signature verification and run arbitrary code in the infotainment system at boot process.
History

Mon, 30 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 28 Jun 2025 15:45:00 +0000

Type Values Removed Values Added
Description A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to the MIB3 ECU to bypass firmware signature verification and run arbitrary code in the infotainment system at boot process.
Title Bypass of secure boot process
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASRG

Published: 2025-06-28T15:37:35.093Z

Updated: 2025-06-30T19:20:40.496Z

Reserved: 2023-03-27T14:51:16.417Z

Link: CVE-2023-28904

cve-icon Vulnrichment

Updated: 2025-06-30T19:19:23.569Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-28T16:15:22.250

Modified: 2025-06-30T20:15:23.153

Link: CVE-2023-28904

cve-icon Redhat

No data.