2023-11-10 09:00:23 +00:00
{
"id" : "CVE-2023-6073" ,
"sourceIdentifier" : "cve@asrg.io" ,
"published" : "2023-11-10T08:15:08.100" ,
2023-11-18 05:00:21 +00:00
"lastModified" : "2023-11-18T03:21:23.573" ,
"vulnStatus" : "Analyzed" ,
2023-11-10 09:00:23 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum via REST API calls.\n"
2023-11-13 05:00:24 +00:00
} ,
{
"lang" : "es" ,
"value" : "El atacante puede realizar un ataque de Denegaci\u00f3n de Servicio para bloquear la ECU ICAS 3 IVI en un Volkswagen ID.3 (y otros veh\u00edculos del Grupo VW con el mismo hardware) y falsificar comandos de configuraci\u00f3n de volumen para activar irreversiblemente el volumen de audio al m\u00e1ximo a trav\u00e9s de llamadas REST API."
2023-11-10 09:00:23 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-11-18 05:00:21 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" ,
"attackVector" : "ADJACENT_NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 6.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.1 ,
"impactScore" : 4.2
} ,
2023-11-10 09:00:23 +00:00
{
"source" : "cve@asrg.io" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" ,
"attackVector" : "ADJACENT_NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 5.7 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.1 ,
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
2023-11-18 05:00:21 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
} ,
2023-11-10 09:00:23 +00:00
{
"source" : "cve@asrg.io" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-20"
} ,
{
"lang" : "en" ,
"value" : "CWE-284"
}
]
}
] ,
2023-11-18 05:00:21 +00:00
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:volkswagen:id.3_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "3.2" ,
"matchCriteriaId" : "5EF1065C-EB08-4BBC-A418-E6DB0AD322B5"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:volkswagen:id.3:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FDFD418D-C4AB-4797-86E4-98462AF5C938"
}
]
}
]
}
] ,
2023-11-10 09:00:23 +00:00
"references" : [
{
"url" : "https://asrg.io/cve-2023-6073-dos-and-control-of-volume-settings-for-vw-id-3-icas3-ivi-ecu/" ,
2023-11-18 05:00:21 +00:00
"source" : "cve@asrg.io" ,
"tags" : [
"Exploit" ,
"Third Party Advisory"
]
2023-11-10 09:00:23 +00:00
}
]
}