Skoda Automotive Cloud: Broken Access Control Vulnerability Exposes User Nicknames and Identifiers

Skoda Automotive Cloud: Broken Access Control Vulnerability Exposes User Nicknames and Identifiers

CVE-2023-28900 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user identifiers of Skoda Connect service users by specifying an arbitrary vehicle VIN number.

Learn more about our Automotive Penetration Testing.