CVE-2020-10558
The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process separation, which allows attackers to disable the speedometer, web browser, climate controls, turn signal visual…
Does this matter?
Lower severity and a low EPSS score (2.60%). Track it; it rarely justifies an emergency change on its own.
Description
The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process separation, which allows attackers to disable the speedometer, web browser, climate controls, turn signal visual and sounds, navigation, autopilot notifications, along with other miscellaneous functions from the main screen.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 2.60% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- tesla/model 3 web interface
- Source
- cve@mitre.org
References
- https://cylect.io/blog/Tesla_Model_3_Vuln/Exploit, Third Party Advisory
- https://safekeepsecurity.com/about/cve-2020-10558/Exploit, Third Party Advisory
- https://cylect.io/blog/Tesla_Model_3_Vuln/Exploit, Third Party Advisory
- https://safekeepsecurity.com/about/cve-2020-10558/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.