CVE-2016-9337
The vehicle's Gateway ECU is susceptible to commands that may allow an attacker to install malicious software allowing the attacker to send messages to the vehicle's CAN bus, a Command Injection.
Does this matter?
Lower severity and a low EPSS score (1.71%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Tesla Motors Model S automobile, all firmware versions before version 7.1 (2.36.31) with web browser functionality enabled. The vehicle's Gateway ECU is susceptible to commands that may allow an attacker to install malicious software allowing the attacker to send messages to the vehicle's CAN bus, a Command Injection.
- CVSS 3.0
- 6.8 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
- EPSS
- 1.71% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- tesla/gateway ecu
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/94697Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-341-01Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/94697Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-341-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.