All Security Advisories
CVE-2023-28895Dec 1, 2023

Hard-coded password for access to power controller chip memory

Description

The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The console allows attackers with physical access to the MIB3 unit to gain full control over the PWC chip.

Advisory Details

Affected Products
MIB3 Infotainment Unit
Problem Type
CWE-259 Use of Hard-coded Password
CAPEC ID
CAPEC-37 Retrieve Embedded Sensitive Data
CVSS Score
3.5
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Published
Dec 1, 2023
View on NVD