CVE-2023-28908 Details
Description
A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving non-fragmented HCI packets on a channel. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.
An integer overflow vulnerability has been identified in the Bluetooth stack of the Volkswagen MIB3 infotainment system, specifically in the 'tsd.bt.phone.mib3' binary, which manages Bluetooth communications. This vulnerability arises from improper validation of user-supplied data when receiving non-fragmented Host Controller Interface (HCI) packets, allowing an attacker to overflow a variable that tracks the total received size of packets. The issue was discovered in a Skoda Superb III vehicle with the MIB3 infotainment unit OEM part number 3V0035820, and is believed to affect several other MIB3 units across various Volkswagen Group models.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 28, 2025CISA-ADP
Assessed Jun 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://i.blackhat.com/EU-24/Presentations/EU-24-Parnishchev-OverTheAirVW.pdf | CISA-ADP | BundleMedia CoverageTechnical Analysis |
| https://asrg.io/security-advisories/vulnerabilities-in-volkswagen-mib3-infotainment-part-2/ | [email protected] | AdvisoryBundleRemedyTechnical Analysis |
| https://i.blackhat.com/EU-24/Presentations/EU-24-Parnishchev-OverTheAirVW.pdf | [email protected] | BundleMedia CoverageTechnical Analysis |
| https://pcacybersecurity.com/resources/advisory/vulnerabilities-in-vw-mib3-infotainment-2 | [email protected] | AdvisoryBundleRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Volkswagen MIB3 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2025 | CVE Modified | CISA-ADP |
| Jun 28, 2025 | New CVE Received | [email protected] |
Volerion