CVE-2016-9337
MEDIUMTesla Motors Model S <7.1 (2.36.31) - Command Injection
Title source: llmDescription
An issue was discovered in Tesla Motors Model S automobile, all firmware versions before version 7.1 (2.36.31) with web browser functionality enabled. The vehicle's Gateway ECU is susceptible to commands that may allow an attacker to install malicious software allowing the attacker to send messages to the vehicle's CAN bus, a Command Injection.
Scores
CVSS v3
6.8
EPSS
0.0095
EPSS Percentile
76.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Classification
CWE
CWE-77
Status
published
Affected Products (2)
tesla/gateway_ecu
n/a/Tesla Gateway ECU on Model S automobile
< Tesla Gateway ECU on Model S automobile
Timeline
Published
Feb 13, 2017
Tracked Since
Feb 18, 2026