CVE Vulnerabilities

CVE-2023-28900

Published: Jan 18, 2024 | Modified: Jan 26, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user identifiers of Skoda Connect service users by specifying an arbitrary vehicle VIN number.

Affected Software

Name Vendor Start Version End Version
Skoda_connect Skoda-auto - (including) - (including)

References