CVE-2020-29439: Medium severity tesla model x vulnerability
Tesla Model X vehicles before 2020-11-23 have key fobs that rely on five VIN digits for the authentication needed for a body control module (BCM) to initiate a Bluetooth wake-up action. (The full VIN is visible from outside the vehicle.)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-29439?
CVE-2020-29439 has been classified as a vulnerability that could potentially allow unauthorized access to the vehicle's body control module.
How do I fix CVE-2020-29439?
To mitigate CVE-2020-29439, owners of affected Tesla Model X vehicles should update their vehicle firmware to the version released on or after 2020-11-23.
Which Tesla Model X vehicles are affected by CVE-2020-29439?
CVE-2020-29439 affects Tesla Model X vehicles manufactured before the firmware update on 2020-11-23.
What does CVE-2020-29439 exploit?
CVE-2020-29439 exploits vulnerabilities in the vehicle's key fob authentication mechanism that relies on partial VIN digits.
Can CVE-2020-29439 lead to vehicle theft?
Yes, CVE-2020-29439 presents a risk of vehicle theft due to the vulnerability in the Bluetooth wake-up action triggered by the key fob.