CVE-2023-32156

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/05/2024
Last modified:
13/08/2025

Description

Tesla Model 3 Gateway Firmware Signature Validation Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. An attacker must first obtain the ability to execute privileged code on the Tesla infotainment system in order to exploit this vulnerability.<br /> <br /> The specific flaw exists within the handling of firmware updates. The issue results from improper error-handling during the update process. An attacker can leverage this vulnerability to execute code in the context of Tesla&amp;#39;s Gateway ECU.<br /> . Was ZDI-CAN-20734.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tesla:model_3_firmware:2023.6:*:*:*:*:*:*:*
cpe:2.3:h:tesla:model_3:-:*:*:*:*:*:*:*