Volkswagen's vulnerability footprint centers on infotainment systems and electric-vehicle charging platforms, including the Discover Media system and the ID.Charger product line and firmware. The recurring exposure reflects weaknesses in input validation and data integrity verification that are characteristic of connected automotive and charging infrastructure, where validation gaps can affect both user experience and operational safety.
The number and severity of CVEs published that impact products developed by Vw over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5684HIGH An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in ord | Jun 6, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-34733MEDIUM A lack of exception handling in the Volkswagen Discover Media Infotainment System Software Version 0876 allows attackers to cause a Denial of Service (DoS) via supplying crafted me | Jun 16, 2023 | 6.8 | 20 | NO | NO |
CVE-2020-28656MEDIUM The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically proximate attackers to execute arbitrary code because some uns | Nov 16, 2020 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vw.
Media articles that mention a CVE ID that affects a product developed by Vw — matched by CVE ID, not by vendor name.