ZDI-25-260: (Pwn2Own) Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass the firewall on the Iris modem in affected Tesla Model S vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firewall service. The issue results from a failure to obtain the xtables lock. An attacker can leverage this vulnerability to bypass firewall rules.
Other sources
This vulnerability allows network-adjacent attackers to bypass the firewall on the Iris modem in affected Tesla Model S vehicles. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2024-6029.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-260?
The severity of ZDI-25-260 is considered critical due to the potential for network-adjacent attackers to bypass the firewall without authentication.
How do I fix ZDI-25-260?
To fix ZDI-25-260, ensure that the Tesla Model S firmware is updated to the latest version provided by Tesla that addresses this vulnerability.
What can attackers do by exploiting ZDI-25-260?
By exploiting ZDI-25-260, attackers can bypass the firewall on the Iris modem in affected Tesla Model S vehicles, potentially gaining unauthorized access.
Which vehicles are affected by ZDI-25-260?
ZDI-25-260 affects Tesla Model S vehicles that are running vulnerable firmware versions.
Is authentication required to exploit ZDI-25-260?
No, authentication is not required to exploit ZDI-25-260, making it particularly dangerous.