Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wqqj-jmr5-3p39

Опубликовано: 04 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.7

Описание

Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed CAN messages to control remote start functions of the vehicle.  Testing completed on Tesla Model 3 vehicles with software version v11.1 (2023.20.9 ee6de92ddac5). This issue affects Model 3: With software versions from 2023.Xx before 2023.44.

Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed CAN messages to control remote start functions of the vehicle.  Testing completed on Tesla Model 3 vehicles with software version v11.1 (2023.20.9 ee6de92ddac5). This issue affects Model 3: With software versions from 2023.Xx before 2023.44.

EPSS

Процентиль: 7%
0.00027
Низкий

4.7 Medium

CVSS4

Дефекты

CWE-74

Связанные уязвимости

nvd
5 месяцев назад

Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed CAN messages to control remote start functions of the vehicle.  Testing completed on Tesla Model 3 vehicles with software version v11.1 (2023.20.9 ee6de92ddac5). This issue affects Model 3: With software versions from 2023.Xx before 2023.44.

EPSS

Процентиль: 7%
0.00027
Низкий

4.7 Medium

CVSS4

Дефекты

CWE-74