PT-2022-20390 · Tesla · Tesla Vehicles

Jedar_Lz

·

Published

2022-09-08

·

Updated

2025-03-24

·

CVE-2022-3093

CVSS v3.1

7.6

High

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tesla vehicles (affected versions not specified)
Description This issue allows physical attackers to execute arbitrary code on affected vehicles. Authentication is not required to exploit this issue. The flaw exists within the ice updater update mechanism due to the lack of proper validation of user-supplied firmware. An attacker can leverage this issue to execute code in the context of root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3093
ZDI-22-1188

Affected Products

Tesla Vehicles