Multiple flaws in Volkswagen Group’s infotainment unit allow for vehicle compromise
ID: 40b0a72b-d008-5b33-95ac-3a9e4279f7fa
STIX ID: report--40b0a72b-d008-5b33-95ac-3a9e4279f7fa
Feed Name: Security Affairs
Researchers from PCAutomotive disclosed a set of vulnerabilities in VW Group MIB3 infotainment units (including units by Preh Car Connect GmbH) that could allow unauthenticated attackers in proximity to exploit Bluetooth/phonebook parsing and other services to cause code execution, track vehicles in real time, access GPS and contacts, monitor speed, record in-car conversations, and more; 12 CVEs are listed, a video PoC was published, and the vendor reports some fixes are deployed while others are being addressed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
