Tesla · Tesla Vehicles · CVE-2022-3093
**Name of the Vulnerable Software and Affected Versions**
Tesla vehicles (affected versions not specified)
**Description**
This issue allows physical attackers to execute arbitrary code on affected vehicles. Authentication is not required to exploit this issue. The flaw exists within the `ice updater` update mechanism due to the lack of proper validation of user-supplied firmware. An attacker can leverage this issue to execute code in the context of `root`.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this issue.