Preh's vulnerability footprint centers on its automotive infotainment systems, particularly the MIB3 platform and associated firmware, with observed issues concentrated in cryptographic and credential-management mechanisms. The recurring weakness classes—inadequate encryption strength, hard-coded credentials, and weak password encoding—reflect the embedded nature of vehicle systems and their integration challenges. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Preh over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28895MEDIUM The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The console allows attackers with physic | Dec 1, 2023 | 6.8 | 21 | NO | NO |
Access to critical Unified Diagnostics Services (UDS) of the Modular Infotainment Platform 3 (MIB3) infotainment is transmitted via Controller Area Network (CAN) bus in a form that | Dec 1, 2023 | 2.4 | 13 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Preh.
Media articles that mention a CVE ID that affects a product developed by Preh — matched by CVE ID, not by vendor name.