Description
The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user identifiers of Skoda Connect service users by specifying an arbitrary vehicle VIN number.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32520 | The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user identifiers of Skoda Connect service users by specifying an arbitrary vehicle VIN number. |
References
| Link | Providers |
|---|---|
| https://asrg.io/security-advisories/cve-2023-28900 |
|
History
Tue, 17 Jun 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: ASRG
Published:
Updated: 2025-06-17T21:19:19.977Z
Reserved: 2023-03-27T14:51:13.968Z
Link: CVE-2023-28900
Updated: 2024-08-02T13:51:39.125Z
Status : Modified
Published: 2024-01-18T17:15:13.737
Modified: 2024-11-21T07:56:14.617
Link: CVE-2023-28900
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD