Volkswagen MIB3 Infotainment是德国大众汽车(Volkswagen)公司的一款汽车上的信息娱乐系统。 Volkswagen MIB3 Infotainment存在安全漏洞,该漏洞源于引导加载程序组件中的RAM缓冲区溢出,可能导致物理访问攻击者绕过固件签名验证并在引导过程中执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Preh Car Connect GmbH (JOYNEXT GmbH) | Volkswagen MIB3 infotainment system MIB3 OI MQB | 0 ~ 0304 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-28910 | 8.0 HIGH | Disabled Abortion Flag |
| CVE-2023-28909 | 8.0 HIGH | Integer Overflow Leading to MTU Bypass |
| CVE-2023-28905 | 8.0 HIGH | Heap buffer overflow in picserver |
| CVE-2023-28906 | 7.8 HIGH | Command injection in networking service |
| CVE-2023-28907 | 6.7 MEDIUM | A lack of access restrictions on internal memory regions |
| CVE-2023-28911 | 6.5 MEDIUM | Arbitrary Channel Disconnection Resulting in Denial of Service |
| CVE-2023-29113 | 6.3 MEDIUM | A lack of access control in custom IPC mechanism |
| CVE-2023-28912 | 5.7 MEDIUM | Cleartext Phonebook Information |
| CVE-2023-28908 | 5.4 MEDIUM | Integer Overflow in Non-Fragmented Data Reception |
| CVE-2023-28902 | 3.3 LOW | Denial of Service via integer underflow in picserver |
| CVE-2023-28903 | 3.3 LOW | Volkswagen MIB3 Infotainment 安全漏洞 |
No comments yet