ID:8768 - Exploit for Input validation error in Tesla Model 3 - CVE-2020-10558
Published: January 24, 2023
Tesla Model 3
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to due to improper process separation in the driving interface. A remote attacker can trick a victim to visit a crafted webpage, crash the chromium-based browser interface and inherently crash the entire Tesla Model 3 interface.
Successful exploitation of this vulnerability allows a remote attacker to disable the speedometer, web browser, climate controls, turn signals, navigation, autopilot notifications, and blinker notifications along with other miscellaneous functions from the main screen.