A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the system to escalate privileges and obtain administrative access to the system.
The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.
Metrics
Affected Vendors & Products
References
History
Mon, 30 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 28 Jun 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the system to escalate privileges and obtain administrative access to the system. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources. | |
Title | Command injection in networking service | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ASRG
Published: 2025-06-28T15:36:47.874Z
Updated: 2025-06-30T19:20:53.245Z
Reserved: 2023-03-27T14:51:16.417Z
Link: CVE-2023-28906

Updated: 2025-06-30T19:19:25.652Z

Status : Awaiting Analysis
Published: 2025-06-28T16:15:22.573
Modified: 2025-06-30T20:15:23.370
Link: CVE-2023-28906

No data.