This vulnerability allows physical attackers to execute arbitrary code on affected Tesla vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ice_updater update mechanism. The issue results from the lack of proper validation of user-supplied firmware. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software | Affected Version | How to fix |
---|---|---|
Tesla Model 3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-CAN-17463 is high due to the potential for arbitrary code execution without authentication.
ZDI-CAN-17463 can be exploited by physical attackers taking advantage of the flawed ice_updater mechanism in affected Tesla vehicles.
ZDI-CAN-17463 specifically affects Tesla Model 3 vehicles.
The potential impacts of ZDI-CAN-17463 include unauthorized control over vehicle functions and data.
Mitigation of ZDI-CAN-17463 involves applying firmware updates provided by Tesla that address the vulnerability.