Description
Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass the firewall on the Iris modem in affected Tesla Model S vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firewall service. The issue results from a failure to obtain the xtables lock. An attacker can leverage this vulnerability to bypass firewall rules. Was ZDI-CAN-23197.
Problem types
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
Product status
2023.44.29 with the AG525RGLAAR01A16M4G_OCPU_02.003.10.003 connectivity card
References
www.zerodayinitiative.com/advisories/ZDI-25-260/ (ZDI-25-260)