Tesla Model S
cpe:2.3:h:tesla:model_s:*:*:*:*:*:*:*, +1 more
A heap-based buffer overflow vulnerability has been identified in the oFono component of Tesla Model S vehicles, allowing local attackers to execute arbitrary code. The vulnerability arises from improper validation of user-supplied data lengths in the parsing of AT command responses, leading to potential code execution in the device's context. To exploit this vulnerability, an attacker must first gain the ability to execute code on the target modem.
Exploitation of this vulnerability allows for arbitrary code execution on the affected vehicle.
This vulnerability has been fixed in Tesla Firmware Version 2024.2.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.