CVE-2023-6073

MEDIUM

Volkswagen ID.3 Firmware < 3.2 - Denial of Service and Volume Setting Spoofing via REST API

Title source: llm
STIX 2.1

Description

Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.

References (1)

Core 1

Scores

CVSS v3 5.7
EPSS 0.0039
EPSS Percentile 31.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-284
Status published
Products (1)
volkswagen/id.3_firmware < 3.2
Published Nov 10, 2023
Tracked Since Feb 18, 2026