Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-29389
HistoryApr 05, 2023 - 4:15 p.m.

Code injection

2023-04-0516:15:00
PRIOn knowledge base
www.prio-n.com
8
toyota rav4
2021
can bus
code injection
vulnerability
unauthorized driving
nvd
attackers

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.7%

Toyota RAV4 2021 vehicles automatically trust messages from other ECUs on a CAN bus, which allows physically proximate attackers to drive a vehicle by accessing the control CAN bus after pulling the bumper away and reaching the headlight connector, and then sending forged “Key is validated” messages via CAN Injection, as exploited in the wild in (for example) July 2022.

CPENameOperatorVersion
rav4_firmwareeq2021

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.7%

Related for PRION:CVE-2023-29389