CVE-2022-3093 – Tesla ice_updater Time-Of-Check Time-Of-Use Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-3093
08 Sep 2022 — This vulnerability allows physical attackers to execute arbitrary code on affected Tesla vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ice_updater update mechanism. The issue results from the lack of proper validation of user-supplied firmware. An attacker can leverage this vulnerability to execute code in the context of root. • https://www.zerodayinitiative.com/advisories/ZDI-22-1188 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •
CVE-2022-27948
https://notcve.org/view.php?id=CVE-2022-27948
27 Mar 2022 — Certain Tesla vehicles through 2022-03-26 allow attackers to open the charging port via a 315 MHz RF signal containing a fixed sequence of approximately one hundred symbols. NOTE: the vendor's perspective is that the behavior is as intended Determinados vehículos Tesla versiones hasta 26-03-2022, permiten a atacantes abrir el puerto de carga por medio de una señal de RF de 315 MHz que contiene una secuencia fija de aproximadamente cien símbolos • https://github.com/pompel123/Tesla-Charging-Port-Opener • CWE-862: Missing Authorization •