Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-37709


Tesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to Authentication Bypass by spoofing. Tesla Model 3's Phone Key authentication is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to open a door and drive the car away by leveraging access to a legitimate Phone Key.


Published

2022-09-16T22:15:12.137

Last Modified

2024-11-21T07:15:05.707

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-290

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tesla model_3_firmware 11.0 Yes
Hardware tesla model_3 - No
Application tesla tesla 4.23 Yes

References