PT-2020-17163 · Tesla · Tesla Model X

Lennert Wouters

·

Published

2020-11-30

·

Updated

2020-12-04

·

CVE-2020-29440

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tesla Model X vehicles before 2020-11-23
Description The issue allows an attacker, who is inside a vehicle or able to send data over the CAN bus, to start and drive the vehicle with a spoofed key fob. This is possible because the vehicles do not perform certificate validation during an attempt to pair a new key fob with the body control module (BCM).
Recommendations For Tesla Model X vehicles before 2020-11-23, update the software to a version that includes certificate validation for key fob pairing to prevent spoofing attacks.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29440

Affected Products

Tesla Model X