Vulnerability Description
Tesla Model 3 vehicles allow attackers to open a door by leveraging access to a legitimate key card, and then using NFC Relay. NOTE: the vendor has developed Pin2Drive to mitigate this issue
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tesla | Model 3 Firmware | - |
| Tesla | Model 3 | - |
References
- https://cansecwest.com/post/2020-03-09-22:00:00_2020_SpeakersThird Party Advisory
- https://twitter.com/Kevin2600/status/1218892338182836224Third Party Advisory
- https://www.carhackingvillage.com/speaker-bios#htm3nrrBroken Link
- https://www.youtube.com/watch?v=VYKsfgox-bsThird Party Advisory
- https://www.youtube.com/watch?v=kQWg-Ywv3S4Third Party Advisory
- https://www.youtube.com/watch?v=nn-_3AbtEkIExploitThird Party Advisory
- https://cansecwest.com/post/2020-03-09-22:00:00_2020_SpeakersThird Party Advisory
- https://twitter.com/Kevin2600/status/1218892338182836224Third Party Advisory
- https://www.carhackingvillage.com/speaker-bios#htm3nrrBroken Link
- https://www.youtube.com/watch?v=VYKsfgox-bsThird Party Advisory
- https://www.youtube.com/watch?v=kQWg-Ywv3S4Third Party Advisory
- https://www.youtube.com/watch?v=nn-_3AbtEkIExploitThird Party Advisory
FAQ
What is CVE-2020-15912?
CVE-2020-15912 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Tesla Model 3 vehicles allow attackers to open a door by leveraging access to a legitimate key card, and then using NFC Relay. NOTE: the vendor has developed Pin2Drive to mitigate this issue
How severe is CVE-2020-15912?
CVE-2020-15912 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15912?
Check the references section above for vendor advisories and patch information. Affected products include: Tesla Model 3 Firmware, Tesla Model 3.