CVE-2023-28907 Details
Description
There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to compromise the CPU core responsible for CAN message processing. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.
A vulnerability exists in the Volkswagen MIB3 infotainment system, specifically in units manufactured by Preh Car Connect GmbH, including the Skoda Superb III model. The issue arises from the absence of memory isolation between CPU cores, allowing an attacker with access to the main operating system to interfere with the CPU core that processes CAN messages. This vulnerability could lead to unauthorized manipulation of vehicle functions via the CAN bus.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 28, 2025CISA-ADP
Assessed Jun 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://i.blackhat.com/EU-24/Presentations/EU-24-Parnishchev-OverTheAirVW.pdf | CISA-ADP | BundleTechnical Analysis |
| https://asrg.io/security-advisories/vulnerabilities-in-volkswagen-mib3-infotainment-part-2/ | [email protected] | AdvisoryBundleTechnical Analysis |
| https://i.blackhat.com/EU-24/Presentations/EU-24-Parnishchev-OverTheAirVW.pdf | [email protected] | BundleTechnical Analysis |
| https://pcacybersecurity.com/resources/advisory/vulnerabilities-in-vw-mib3-infotainment-2 | [email protected] | AdvisoryBundleTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Volkswagen MIB3 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2025 | CVE Modified | CISA-ADP |
| Jun 28, 2025 | New CVE Received | [email protected] |
Volerion