Description
An integer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause a denial-of-service of the infotainment system.
Problem types
CWE-190 Integer Overflow or Wraparound
Product status
Any version
Credits
Artem Ivachev from PCA Cyber Security (PCAutomotive)
References
i.blackhat.com/...tations/EU-24-Parnishchev-OverTheAirVW.pdf
i.blackhat.com/...tations/EU-24-Parnishchev-OverTheAirVW.pdf
pcacybersecurity.com/...rabilities-in-vw-mib3-infotainment-2
asrg.io/...abilities-in-volkswagen-mib3-infotainment-part-2/