CVE-2023-32156
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/05/2024
Last modified:
13/08/2025
Description
Tesla Model 3 Gateway Firmware Signature Validation Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. An attacker must first obtain the ability to execute privileged code on the Tesla infotainment system in order to exploit this vulnerability.<br />
<br />
The specific flaw exists within the handling of firmware updates. The issue results from improper error-handling during the update process. An attacker can leverage this vulnerability to execute code in the context of Tesla&#39;s Gateway ECU.<br />
. Was ZDI-CAN-20734.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tesla:model_3_firmware:2023.6:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tesla:model_3:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



