CVE-2023-28899

MEDIUM

Skoda Superb 3 Firmware - Denial of Service via UDS Reset Request

Title source: llm
STIX 2.1

Description

By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdown and denial of service of other vehicle components even when the vehicle is moving at a high speed. No safety critical functions affected. 

References (1)

Core 1
Core References

Scores

CVSS v3 4.7
EPSS 0.0014
EPSS Percentile 3.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (1)
skoda-auto/superb_3_firmware
Published Jan 12, 2024
Tracked Since Feb 18, 2026