CVE-2020-10558 describes a Denial of Service vulnerability in the Tesla Model 3 driving interface (versions prior to 2020.4.10) due to improper process separation. This flaw allows an attacker to disable critical functions like the speedometer, climate controls, navigation, and autopilot notifications from the main screen. With a CVSS score of 6.5 (Medium), this vulnerability has a network attack vector and low attack complexity, leading to high availability impact. While no public exploit code or active exploitation has been observed, it has garnered moderate community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2020.4.10CPE matchmatch criteria | cpe:2.3:a:tesla:model_3_web_interface:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.