First published: Mon Nov 30 2020(Updated: )
Tesla Model X vehicles before 2020-11-23 have key fobs that rely on five VIN digits for the authentication needed for a body control module (BCM) to initiate a Bluetooth wake-up action. (The full VIN is visible from outside the vehicle.)
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tesla Model X | <2020-11-23 | |
Tesla Model X Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29439 has been classified as a vulnerability that could potentially allow unauthorized access to the vehicle's body control module.
To mitigate CVE-2020-29439, owners of affected Tesla Model X vehicles should update their vehicle firmware to the version released on or after 2020-11-23.
CVE-2020-29439 affects Tesla Model X vehicles manufactured before the firmware update on 2020-11-23.
CVE-2020-29439 exploits vulnerabilities in the vehicle's key fob authentication mechanism that relies on partial VIN digits.
Yes, CVE-2020-29439 presents a risk of vehicle theft due to the vulnerability in the Bluetooth wake-up action triggered by the key fob.