Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: ASRG
Published: 2023-11-10T07:32:16.964Z
Updated: 2024-08-02T08:21:17.281Z
Reserved: 2023-11-10T07:06:53.421Z
Link: CVE-2023-6073
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-11-10T08:15:08.100
Modified: 2024-11-21T08:43:05.450
Link: CVE-2023-6073
Redhat
No data.