← Back

CVE-2023-6073

nvd nist
Published: Nov 10, 2023Modified: Nov 21, 2024

JSON object

Loading...
6.3
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Exploitability: 2.1 / Impact: 4.2
Source: NVD

Description

Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.

Affected (1)

1 product
Id.3 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.2
Running on/withPlatform Versions
Volkswagen
Id.3
All versions

References (2)

Timeline

No history available yet.