Tesla Model 3 bsa_server BIP Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability
CVE-2023-32157

7.5HIGH

Key Information:

Vendor

Tesla

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-32157?

This vulnerability involves a heap-based buffer overflow within the bsa_server process of Tesla Model 3 vehicles. Attackers with network access can exploit this flaw by pairing a malicious Bluetooth device to execute arbitrary code on the vehicle's systems. The underlying issue stems from improper validation of length for user-supplied data prior to it being copied into a fixed-length heap-based buffer. Successful exploitation yields the ability to execute code in the context of an unprivileged user in a sandboxed environment, potentially compromising the vehicle's operational integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Model 3 Model 3 - 2023.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.