#VU112034 Integer underflow in MIB3 - CVE-2023-28902
Published: June 30, 2025
MIB3
Volkswagen
Description
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer underflow in picture handler during EXIF data parsing. An attacker with physical access can attach a USB flash drive containing a specifically crafted JPEG image, trigger integer underflow and cause a denial of service condition on the target system.