Lucene search

K
cveMitreCVE-2023-29389
HistoryApr 05, 2023 - 4:15 p.m.

CVE-2023-29389

2023-04-0516:15:08
CWE-74
mitre
web.nvd.nist.gov
26
toyota
rav4
2021
can bus
vulnerability
cve-2023-29389
nvd
security
automotive

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

29.8%

Toyota RAV4 2021 vehicles automatically trust messages from other ECUs on a CAN bus, which allows physically proximate attackers to drive a vehicle by accessing the control CAN bus after pulling the bumper away and reaching the headlight connector, and then sending forged “Key is validated” messages via CAN Injection, as exploited in the wild in (for example) July 2022.

Affected configurations

Nvd
Node
toyotarav4Match-
AND
toyotarav4_firmwareMatch2021
VendorProductVersionCPE
toyotarav4-cpe:2.3:h:toyota:rav4:-:*:*:*:*:*:*:*
toyotarav4_firmware2021cpe:2.3:o:toyota:rav4_firmware:2021:*:*:*:*:*:*:*

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

29.8%

Related for CVE-2023-29389