Vulnerability Description
An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A heap-based buffer overflow allows remote attackers to cause a denial of service or execute arbitrary code via malformed Wi-Fi packets.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Marvell | 88W8688 Firmware | < p52 |
| Marvell | 88W8688 | - |
Related Weaknesses (CWE)
References
- https://keenlab.tencent.com/en/2020/01/02/exploiting-wifi-stack-on-tesla-model-s
- https://www.marvell.com/documents/ioaj5dntk2ubykssa78s/Vendor Advisory
- https://keenlab.tencent.com/en/2020/01/02/exploiting-wifi-stack-on-tesla-model-s
- https://www.marvell.com/documents/ioaj5dntk2ubykssa78s/Vendor Advisory
FAQ
What is CVE-2019-13581?
CVE-2019-13581 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A h...
How severe is CVE-2019-13581?
CVE-2019-13581 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-13581?
Check the references section above for vendor advisories and patch information. Affected products include: Marvell 88W8688 Firmware, Marvell 88W8688.