Buffer overflow in MIB3 - CVE-2023-28904

 

Buffer overflow in MIB3 - CVE-2023-28904

Published: June 30, 2025


Vulnerability identifier: #VU112036
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28904
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to execute arbitrary code on the target system.

The vulnerability exists due to a logic flaw in the bootloader component. An attacker with physical access can trigger memory corruption to bypass firmware signature verification and execute arbitrary code in the infotainment system at boot process.


Affected software

MIB3

How to mitigate CVE-2023-28904

Install updates from vendor's website.


External References

Related Security Bulletins