Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
DoS and Control of Volume Settings for VW ID.3 ICAS3 IVI ECU
Vulnerability Description
Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
访问控制不恰当
Vulnerability Title
Volkswagen ID.3 安全漏洞
Vulnerability Description
Volkswagen ID.3是德国大众汽车(Volkswagen)公司的一款纯电动汽车。 Volkswagen ID.3 ICAS 3 IVI ECU存在安全漏洞,该漏洞源于允许攻击者造成拒绝服务(DOS),并通过REST API调用spoof volume setting命令,以不可逆地将音量打开到最大。
CVSS Information
N/A
Vulnerability Type
N/A