CVE-2023-28900: Skoda-Auto Skoda Connect
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user identifiers of Skoda Connect service users by specifying an arbitrary vehicle VIN number.
Affected products
- Skoda-Auto Skoda Connect: affected versions not specified
Published 2024-01-18. Last modified 2026-06-17.