Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: ASRG
Published: 2023-11-10T07:32:16.964Z
Updated: 2025-02-27T20:34:00.676Z
Reserved: 2023-11-10T07:06:53.421Z
Link: CVE-2023-6073
Updated: 2024-08-02T08:21:17.281Z
Status : Modified
Published: 2023-11-10T08:15:08.100
Modified: 2024-11-21T08:43:05.450
Link: CVE-2023-6073
No data.