CVE-2020-29440

MEDIUM

Tesla Model X Firmware < 2020-11-23 - Improper Certificate Validation in Key Fob Pairing

Title source: llm
STIX 2.1

Description

Tesla Model X vehicles before 2020-11-23 do not perform certificate validation during an attempt to pair a new key fob with the body control module (BCM). This allows an attacker (who is inside a vehicle, or is otherwise able to send data over the CAN bus) to start and drive the vehicle with a spoofed key fob.

References (1)

Core 1
Core References
Exploit, Press/Media Coverage, Third Party Advisory x_refsource_misc
https://www.wired.com/story/tesla-model-x-hack-bluetooth/

Scores

CVSS v3 4.6
EPSS 0.0021
EPSS Percentile 11.2%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-295
Status published
Products (1)
tesla/model_x_firmware < 2020-11-23
Published Nov 30, 2020
Tracked Since Feb 18, 2026