CVE-2023-28901

MEDIUM

Skoda Connect - Unauthenticated Exposure of Sensitive Vehicle Data via VIN Parameter

Title source: llm
STIX 2.1

Description

The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum speed, and other information of Skoda Connect service users by specifying an arbitrary vehicle VIN number.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0051
EPSS Percentile 39.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
skoda-auto/skoda_connect
Published Jan 18, 2024
Tracked Since Feb 18, 2026