Skip to main content

Vendor archive

tesla CVEs

Beta · best-effort

24 CVEs tagged to vendor tesla0 Critical, 14 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2025-2082

Published Apr 30, 2025

Tesla Model 3 VCSEC Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6032

Published Apr 30, 2025

Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model S veh…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6031

Published Apr 30, 2025

Tesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6030

Published Apr 30, 2025

Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected Tesla Model S vehicles. An att…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6029

Published Apr 30, 2025

Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass the firewall on the Iris modem in affected Te…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13943

Published Apr 30, 2025

Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affecte…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32156

Published May 3, 2024

Tesla Model 3 Gateway Firmware Signature Validation Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32155

Published May 3, 2024

Tesla Model 3 bcmdhd Out-Of-Bounds Write Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected Tesla Model 3 vehic…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42431

Published Mar 29, 2023

This vulnerability allows local attackers to escalate privileges on affected Tesla vehicles. An attacker must first obtain the ability to execute privileged code on the target sys…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42430

Published Mar 29, 2023

This vulnerability allows local attackers to escalate privileges on affected Tesla vehicles. An attacker must first obtain the ability to execute privileged code on the target sys…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9306

Published Feb 18, 2021

Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to store the cleartext password…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-29440

Published Nov 30, 2020

Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob with the body control module (BCM). This allows an attacker…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29439

Published Nov 30, 2020

Tesla Model X vehicles before 2020-11-23 have key fobs that rely on five VIN digits for the authentication needed for a body control module (BCM) to initiate a Bluetooth wake-up a…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29438

Published Nov 30, 2020

Tesla Model X vehicles before 2020-11-23 have key fobs that accept firmware updates without signature verification. This allows attackers to construct firmware that retrieves an u…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15912

Published Jul 23, 2020

Tesla Model 3 vehicles allow attackers to open a door by leveraging access to a legitimate key card, and then using NFC Relay. NOTE: the vendor has developed Pin2Drive to mitigate…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10558

Published Mar 20, 2020

The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process separation, which allows attackers to dis…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-9977

Published Mar 24, 2019

The renderer process in the entertainment system on Tesla Model 3 vehicles mishandles JIT compilation, which allows attackers to trigger firmware code execution, and display a cra…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9337

Published Feb 13, 2017

An issue was discovered in Tesla Motors Model S automobile, all firmware versions before version 7.1 (2.36.31) with web browser functionality enabled. The vehicle's Gateway ECU is…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1