CVE-2023-28900

Publication date

2024-01-18 16:23:07

Family

ASRG

State

PUBLISHED

Description

The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user identifiers of Skoda Connect service users by specifying an arbitrary vehicle VIN number.