ZDI-CAN-20733: ZDI-23-971: (Pwn2Own) Tesla Model 3 bcmdhd Out-Of-Bounds Write Local Privilege Escalation Vulnerability
Published Jul 18, 2023
·Updated
This vulnerability allows local attackers to escalate privileges on affected Tesla Model 3 vehicles. An attacker must first obtain the ability to execute code on the wifi subsystem in order to exploit this vulnerability.
Affected Software
1 affected component
Tesla Model 3
Event History
Jul 18, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Feb 24, 2025
Advisory Published
via ZDI·08:24 AM
Frequently Asked Questions
1
What is the severity of ZDI-CAN-20733?
The severity of ZDI-CAN-20733 is critical, as it allows local attackers to escalate privileges.
2
How do I fix ZDI-CAN-20733?
To fix ZDI-CAN-20733, ensure that your Tesla Model 3 software is updated to the latest version provided by Tesla.
3
Who is affected by ZDI-CAN-20733?
Only the Tesla Model 3 vehicles are affected by the ZDI-CAN-20733 vulnerability.
4
What type of attacks does ZDI-CAN-20733 enable?
ZDI-CAN-20733 enables local attackers to escalate privileges on the affected vehicles.
5
What is required to exploit ZDI-CAN-20733?
To exploit ZDI-CAN-20733, an attacker must first obtain the ability to execute code on the wifi subsystem.