CVE-2023-32157

T

esla Model 3 bsa_server BIP Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the bsa_server process. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of an unprivileged user in a sandboxed process. . Was ZDI-CAN-20737.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tesla:model_3_firmware:2023.6:*:*:*:*:*:*:*
cpe:2.3:h:tesla:model_3:-:*:*:*:*:*:*:*

History

13 Aug 2025, 12:35

Type Values Removed Values Added
CWE CWE-787
CVSS v2 : unknown
v3 : 4.6
v2 : unknown
v3 : 7.5
References () https://www.zerodayinitiative.com/advisories/ZDI-23-973/ - () https://www.zerodayinitiative.com/advisories/ZDI-23-973/ - Third Party Advisory
CPE cpe:2.3:h:tesla:model_3:-:*:*:*:*:*:*:*
cpe:2.3:o:tesla:model_3_firmware:2023.6:*:*:*:*:*:*:*
First Time Tesla model 3 Firmware
Tesla
Tesla model 3

21 Nov 2024, 08:02

Type Values Removed Values Added
References () https://www.zerodayinitiative.com/advisories/ZDI-23-973/ - () https://www.zerodayinitiative.com/advisories/ZDI-23-973/ -

18 Sep 2024, 19:15

Type Values Removed Values Added
Summary (en) Tesla Model 3 bsa_server BIP Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the bsa_server process. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of an unprivileged user in a sandboxed process. Was ZDI-CAN-20737. (en) Tesla Model 3 bsa_server BIP Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the bsa_server process. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of an unprivileged user in a sandboxed process. . Was ZDI-CAN-20737.

03 May 2024, 12:50

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-03 02:15

Updated : 2025-08-13 12:35


NVD link : CVE-2023-32157

Mitre link : CVE-2023-32157

CVE.ORG link : CVE-2023-32157


JSON object : View

Products Affected
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write