CVE-2024-13943
Last modified
CVE-2024-13943 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected affected Tesla Model S vehicles. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected affected Tesla Model S vehicles. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the QCMAP_ConnectionManager component. An attacker can abuse the service to assign LAN addresses to the WWAN. An attacker can leverage this vulnerability to access network services that were only intended to be exposed to the internal LAN. Was ZDI-CAN-23199.
Metrics
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tesla | Model S Firmware | < 2024.8 |
References
- https://www.zerodayinitiative.com/advisories/ZDI-25-262/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-13943?
How severe is CVE-2024-13943?
How do I fix CVE-2024-13943?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-13931Relative Path Traversal vulnerabilities in ASPECT allow acce…7.5
- CVE-2024-13933The FoodBakery | Delivery Restaurant Directory WordPress The…8.8
- CVE-2024-13939String::Compare::ConstantTime for Perl through 0.321 is vuln…7.5
- CVE-2024-1394A memory leak flaw was found in Golang in the RSA encrypting…7.5
- CVE-2024-13940The Ninja Forms Webhooks plugin for WordPress is vulnerable …5.5
- CVE-2024-13941A vulnerability was found in ouch-org ouch up to 0.3.1. It h…5.3
- CVE-2024-13944Link Following Local Privilege Escalation Vulnerability in N…7.8
- CVE-2024-13945Stored Absolute Path Traversal vulnerabilities in ASPECT cou…8.4
- CVE-2024-13946DLL's are not digitally signed when loaded in ASPECT's confi…7.1
- CVE-2024-13947Device commissioning parameters in ASPECT may be modified by…7.1
- CVE-2024-13948Windows permissions for ASPECT configuration toolsets are no…7.3
- CVE-2024-13949Large content vulnerabilities are present in ASPECT exposing…6.9
Are you affected by CVE-2024-13943?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
