CVE-2023-28896 describes a low-severity vulnerability affecting Preh MIB3 infotainment systems, specifically observed in a 2022 Skoda Superb III. It allows an attacker with physical access to the vehicle to intercept and decode critical Unified Diagnostics Services (UDS) data transmitted over the CAN bus. The CVSS score is 2.4 (LOW), indicating a physical attack vector with low complexity and a potential impact of limited confidentiality loss. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0304CPE matchmatch criteria | cpe:2.3:o:preh:mib3_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.