A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to the MIB3 ECU to bypass firmware signature verification and run arbitrary code in the infotainment system at boot process.
References
Configurations
No configuration.
History
30 Jun 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://i.blackhat.com/EU-24/Presentations/EU-24-Parnishchev-OverTheAirVW.pdf - |
30 Jun 2025, 18:38
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
28 Jun 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-28 16:15
Updated : 2025-06-30 20:15
NVD link : CVE-2023-28904
Mitre link : CVE-2023-28904
CVE.ORG link : CVE-2023-28904
JSON object : View
Products Affected
No product.
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')