5.3

CVE-2022-37709

Exploit
Tesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to Authentication Bypass by spoofing. Tesla Model 3's Phone Key authentication is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to open a door and drive the car away by leveraging access to a legitimate Phone Key.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TeslaModel 3 Firmware Version11.0
   TeslaModel 3 Version-
TeslaTesla Version4.23 SwPlatformandroid
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.414
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 1.6 3.6
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-290 Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

https://fmsh-seclab.github.io/
Third Party Advisory
Exploit
Technical Description
https://github.com/fmsh-seclab/TesMla
Third Party Advisory
https://youtu.be/cPhYW5FzA9A
Third Party Advisory
Exploit