CVE-2020-29440: Medium severity tesla model x vulnerability
Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob with the body control module (BCM). This allows an attacker (who is inside a vehicle, or is otherwise able to send data over the CAN bus) to start and drive the vehicle with a spoofed key fob.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-29440?
The severity of CVE-2020-29440 is considered high due to the potential for unauthorized access to the vehicle.
How do I fix CVE-2020-29440?
To fix CVE-2020-29440, ensure your Tesla Model X is updated to firmware version 2020-11-23 or later.
Who is affected by CVE-2020-29440?
CVE-2020-29440 affects Tesla Model X vehicles manufactured before the firmware update on 2020-11-23.
What can an attacker do exploiting CVE-2020-29440?
An attacker exploiting CVE-2020-29440 can potentially start and drive the vehicle without authorization.
What component of the Tesla Model X is vulnerable in CVE-2020-29440?
The vulnerable component in CVE-2020-29440 is the body control module (BCM) during key fob pairing.