CVE-2023-28905: Heap buffer overflow in picserver
A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28905?
CVE-2023-28905 has a high severity rating due to the potential for arbitrary code execution.
How does CVE-2023-28905 affect the MIB3 infotainment unit?
CVE-2023-28905 allows an attacker to exploit a heap buffer overflow, potentially leading to code execution on the MIB3 infotainment unit.
What vehicles are impacted by CVE-2023-28905?
CVE-2023-28905 primarily affects Skoda vehicles equipped with the MIB3 infotainment unit.
How do I mitigate CVE-2023-28905?
To mitigate CVE-2023-28905, it is recommended to update the firmware of the MIB3 infotainment unit with the latest security patches provided by the manufacturer.
Can CVE-2023-28905 be exploited remotely?
Yes, CVE-2023-28905 could potentially be exploited remotely if an attacker can deliver a specially crafted image file to the MIB3 infotainment unit.