Vulnerability Description
Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download car information without authentication.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Audi | Universal Traffic Recorder Firmware | 1.52 |
| Audi | Universal Traffic Recorder | 2.0 |
Related Weaknesses (CWE)
References
- https://2barbie.notion.site/2024-Audi-UTR-2-0-Report-1bff0be688c680cb8795efe7873ExploitThird Party Advisory
FAQ
What is CVE-2025-45584?
CVE-2025-45584 is a vulnerability with a CVSS score of 7.5 (HIGH). Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download car information without authentication.
How severe is CVE-2025-45584?
CVE-2025-45584 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-45584?
Check the references section above for vendor advisories and patch information. Affected products include: Audi Universal Traffic Recorder Firmware, Audi Universal Traffic Recorder.