#VU112041 Improper access control in MIB3 - CVE-2023-28907
Published: June 30, 2025
MIB3
Volkswagen
Description
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in CARCOM memory. A local administrator can bypass implemented security restrictions, execute arbitrar code and read/write to the Infotainment CAN bus of the target vehicle.