ZDI-CAN-20737: ZDI-23-973: (Pwn2Own) Tesla Model 3 bsa_server BIP Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20737?
The severity of ZDI-CAN-20737 is high due to the potential for remote arbitrary code execution.
How do I fix ZDI-CAN-20737?
To fix ZDI-CAN-20737, ensure your Tesla Model 3 is updated with the latest software version provided by Tesla.
What vehicles are affected by ZDI-CAN-20737?
ZDI-CAN-20737 specifically affects Tesla Model 3 vehicles.
Can an attacker exploit ZDI-CAN-20737 remotely?
An attacker cannot exploit ZDI-CAN-20737 remotely without first pairing a malicious Bluetooth device with the target system.
What type of attack does ZDI-CAN-20737 enable?
ZDI-CAN-20737 enables network-adjacent attackers to execute arbitrary code on the affected Tesla Model 3 vehicles.