CVE Vulnerabilities

CVE-2023-6073

Published: Nov 10, 2023 | Modified: Nov 18, 2023
CVSS 3.x
6.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.

Affected Software

Name Vendor Start Version End Version
Id.3_firmware Volkswagen * 3.2 (excluding)

References