All Security Advisories
CVE-2023-28900Jan 18, 2024

Nickname Disclosure on the Backend Automotive Server

Description

An attacker can receive nickname and other identifiers of Škoda Connect users by arbitrary VIN number (CVE-2023-28900). This issue is categorized as Broken Access Control vulnerability. An attacker can act outside of the intended permissions that allows him to get extended information on the car’s owner.

Advisory Details

Affected Products
Skoda Connect
Problem Type
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CAPEC ID
CAPEC-116 Excavation
CVSS Score
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published
Jan 18, 2024
View on NVD