kentindell.github.io
https://kentindell.github.io/2023/04/03/can-injection CVE-2023-29389
MEDIUM
toyota rav4_firmware Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Record summary
CVE-2023-29389 has a selected CVSS score of 6.8 (medium).
Description
Toyota RAV4 2021 vehicles automatically trust messages from other ECUs on a CAN bus, which allows physically proximate attackers to drive a vehicle by accessing the control CAN bus after pulling the bumper away and reaching the headlight connector, and then sending forged "Key is validated" messages via CAN Injection, as exploited in the wild in (for example) July 2022.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 5, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 12, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
rav4_firmwareBrowse toyota / rav4_firmware | VulnCheck | Version data not supplied | |
References
3news.ycombinator.com
https://news.ycombinator.com/item?id=35452963 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-29389