CVE-2022-37709
Tesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to Authentication Bypass by spoofing. Tesla Model 3's Phone Key authentication is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to open a door and drive the car away by leveraging access to a legitimate Phone Key.
- Affected products
- Tesla Model 3, Tesla Mobile App
- Tesla Model 3 Firmware
- = 11.0
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 0.6% (44th percentile)
- Weakness
- CWE-290
- NVD status
- Modified
- Published
- 2022-09-16
CVE-2022-37709 at NVD
No indexed exploits for CVE-2022-37709 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-37709 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.