Skoda Automotive Cloud: Broken Access Control Vulnerability Exposes User Data

Skoda Automotive Cloud: Broken Access Control Vulnerability Exposes User Data

CVE-2023-28901 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum speed, and other information of Skoda Connect service users by specifying an arbitrary vehicle VIN number.

Learn more about our Automotive Penetration Testing.