CVE-2022-37709: Medium severity tesla model 3 firmware vulnerability
Published Sep 16, 2022
·Updated
Tesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to Authentication Bypass by spoofing. Tesla Model 3's Phone Key authentication is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to open a door and drive the car away by leveraging access to a legitimate Phone Key.
Affected Software
3 affected components
Tesla Model 3 Firmware=11.0
Tesla Model 3
Tesla Tesla Android=4.23
Event History
Sep 16, 2022
CVE Published
via MITRE·08:43 PM
Data Sourced
via MITRE·08:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Tesla Model 3 vulnerability?
The vulnerability ID is CVE-2022-37709.
2
What is the severity of CVE-2022-37709?
The severity of CVE-2022-37709 is medium (5.3).
3
How does the vulnerability in Tesla Model 3 authentication bypass work?
The vulnerability allows for authentication bypass by spoofing in the Tesla Model 3 mobile app, potentially enabling unauthorized access to the vehicle.
4
Which version of Tesla Model 3 firmware is affected by CVE-2022-37709?
CVE-2022-37709 affects Tesla Model 3 firmware version 11.0.
5
Is Tesla Model 3 hardware also vulnerable to CVE-2022-37709?
No, the Tesla Model 3 hardware is not vulnerable to CVE-2022-37709.