Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jv36-m28h-q393

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob with the body control module (BCM). This allows an attacker (who is inside a vehicle, or is otherwise able to send data over the CAN bus) to start and drive the vehicle with a spoofed key fob.

Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob with the body control module (BCM). This allows an attacker (who is inside a vehicle, or is otherwise able to send data over the CAN bus) to start and drive the vehicle with a spoofed key fob.

EPSS

Процентиль: 21%
0.00066
Низкий

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 4.6
nvd
около 5 лет назад

Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob with the body control module (BCM). This allows an attacker (who is inside a vehicle, or is otherwise able to send data over the CAN bus) to start and drive the vehicle with a spoofed key fob.

EPSS

Процентиль: 21%
0.00066
Низкий

Дефекты

CWE-295