Tesla Model S
cpe:2.3:h:tesla:model_s:*:*:*:*:*:*:*, +1 more
A race condition vulnerability has been identified in the Iris modem of Tesla Model S vehicles, allowing network-adjacent attackers to bypass the firewall. This issue arises from the firewall service's failure to properly manage the xtables lock, enabling attackers to manipulate firewall rules. Notably, no authentication is required to exploit this vulnerability.
Exploitation of this vulnerability allows for unauthorized firewall rule manipulation, potentially leading to unauthorized network access or interference.
This vulnerability has been fixed in Tesla firmware version 2024.2.3.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.