Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6032

Опубликовано: 30 апр. 2025
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code on the target system in order to exploit this vulnerability.

The specific flaw exists within the ql_atfwd process. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code on the target modem in the context of root. Was ZDI-CAN-23201.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:tesla:model_s_firmware:*:*:*:*:*:*:*:*
Версия до 2024.8 (исключая)
cpe:2.3:h:tesla:model_s:-:*:*:*:*:*:*:*

EPSS

Процентиль: 17%
0.00054
Низкий

7.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.8
github
9 месяцев назад

Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code on the target system in order to exploit this vulnerability. The specific flaw exists within the ql_atfwd process. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code on the target modem in the context of root. Was ZDI-CAN-23201.

EPSS

Процентиль: 17%
0.00054
Низкий

7.8 High

CVSS3

Дефекты

CWE-78