CVE-2023-29389
Last modified
CVE-2023-29389 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Toyota RAV4 2021 vehicles automatically trust messages from other ECUs on a CAN bus, which allows physically proximate attackers to drive a vehicle by accessing the control CAN bus after pulling the bumper away and reaching the headlight connector, and then sending forged "Key is validated" messages via CAN Injection, as exploited in the wild in (for example) July 2022.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
Toyota RAV4 2021 vehicles automatically trust messages from other ECUs on a CAN bus, which allows physically proximate attackers to drive a vehicle by accessing the control CAN bus after pulling the bumper away and reaching the headlight connector, and then sending forged "Key is validated" messages via CAN Injection, as exploited in the wild in (for example) July 2022.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Toyota | Rav4 Firmware | 2021 |
References
- https://kentindell.github.io/2023/04/03/can-injection/Exploit, Third Party Advisory
- https://news.ycombinator.com/item?id=35452963Issue Tracking
- https://kentindell.github.io/2023/04/03/can-injection/Exploit, Third Party Advisory
- https://news.ycombinator.com/item?id=35452963Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-29389?
How severe is CVE-2023-29389?
How do I fix CVE-2023-29389?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-29383In Shadow 4.13, it is possible to inject control characters …3.3
- CVE-2023-29384Unrestricted Upload of File with Dangerous Type vulnerabilit…9.8
- CVE-2023-29385Unauth. Reflected Cross-Site Scripting (XSS) vulnerability i…6.1
- CVE-2023-29386Unrestricted Upload of File with Dangerous Type vulnerabilit…9.1
- CVE-2023-29387Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulne…5.4
- CVE-2023-29388Unauth. Reflected Cross-Site Scripting (XSS) vulnerability i…6.1
- CVE-2023-2939Insufficient data validation in Installer in Google Chrome o…7.8
- CVE-2023-2940Inappropriate implementation in Downloads in Google Chrome p…6.5
- CVE-2023-29400Templates containing actions in unquoted HTML attributes (e.…7.3
- CVE-2023-29401The filename parameter of the Context.FileAttachment functio…4.3
- CVE-2023-29402The go command may generate unexpected code at build time wh…9.8
- CVE-2023-29403On Unix platforms, the Go runtime does not behave differentl…7.8
Are you affected by CVE-2023-29389?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
