Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.
References
Link | Resource |
---|---|
https://asrg.io/cve-2023-6073-dos-and-control-of-volume-settings-for-vw-id-3-icas3-ivi-ecu/ | Exploit Third Party Advisory |
https://asrg.io/cve-2023-6073-dos-and-control-of-volume-settings-for-vw-id-3-icas3-ivi-ecu/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 08:43
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-10 08:15
Updated : 2024-11-21 08:43
NVD link : CVE-2023-6073
Mitre link : CVE-2023-6073
CVE.ORG link : CVE-2023-6073
JSON object : View
Products Affected
volkswagen
- id.3_firmware
- id.3
CWE