Vulnerabilities > CVE-2023-28901 - Unspecified vulnerability in Skoda-Auto Skoda Connect
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum speed, and other information of Skoda Connect service users by specifying an arbitrary vehicle VIN number.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |