CVE-2022-23126
Summary
| CVE | CVE-2022-23126 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-24 19:15:00 UTC |
| Updated | 2023-11-07 03:44:00 UTC |
| Description | TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Teslamate Project | Teslamate | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release v1.25.1 · adriankumpf/teslamate · GitHub | CONFIRM | github.com | |
| Teslascope on Twitter: "Just to chime in, any vehicles on TezLab were not at any risk of "full remote control" and as such, vehicles whether on TezLab or other services were not related to this. ???? David's thread pertains to a vulnerability in Teslamate, now patched. https://t.co/bv3EH5uDmI… https://t.co/9mEm3lPlnQ" | MISC | twitter.com | |
| How I got access to 25+ Tesla’s around the world. By accident. And curiosity. | by David Colombo | Jan, 2022 | Medium | MISC | medium.com | |
| How I got access to 25+ Tesla’s around the world. By accident. And curiosity. | by David Colombo | Medium | medium.com | ||
| Comparing v1.25.0...v1.25.1 · adriankumpf/teslamate · GitHub | MISC | github.com | |
| Disable anonymous login to Grafana · adriankumpf/teslamate@fff6915 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.