CVE-2020-29438: Medium severity tesla model x vulnerability
Tesla Model X vehicles before 2020-11-23 have key fobs that accept firmware updates without signature verification. This allows attackers to construct firmware that retrieves an unlock code from a secure enclave chip.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-29438?
CVE-2020-29438 is considered to have a high severity as it allows attackers to potentially unlock vehicles by exploiting the firmware update process.
How do I fix CVE-2020-29438?
To fix CVE-2020-29438, Tesla owners should update their vehicle's firmware to the version released on or after 2020-11-23.
What type of vehicles are impacted by CVE-2020-29438?
CVE-2020-29438 affects Tesla Model X vehicles manufactured before November 23, 2020.
What exploit does CVE-2020-29438 enable?
CVE-2020-29438 enables attackers to create unauthorized firmware updates that can retrieve unlock codes from a secure enclave chip.
Is the key fob of Tesla Model X secure in light of CVE-2020-29438?
The key fob of Tesla Model X is vulnerable under CVE-2020-29438 due to the lack of signature verification for firmware updates.