Buffer overflow in MIB3 - CVE-2023-28904

 

Buffer overflow in MIB3 - CVE-2023-28904

Published: June 30, 2025


Vulnerability identifier: #VU112036
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-28904
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Volkswagen
Affected software:
MIB3

Detailed vulnerability description

The vulnerability allows a local attacker to execute arbitrary code on the target system.

The vulnerability exists due to a logic flaw in the bootloader component. An attacker with physical access can trigger memory corruption to bypass firmware signature verification and execute arbitrary code in the infotainment system at boot process.


How to mitigate CVE-2023-28904

Install updates from vendor's website.

Sources