Model 3
Vendor:
First CVE: Mar 24, 2019 · Active for 7 years
11
Total CVEs
More Total CVEs than 89% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Model 3 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 24, 2019
7 years ago
Most Recent CVE
Apr 30, 2025
451 days ago
CVE Severity & Scoring
Model 311 CVEs
36%
64%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (27.3%)
Network1 (9.1%)
Unknown0 (0.0%)
Physical1 (9.1%)
Adjacent Network6 (54.5%)
Attack Complexity
Low6 (54.5%)
High5 (45.5%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low3 (27.3%)
High0 (0.0%)
None8 (72.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32156HIGH Tesla Model 3 Gateway Firmware Signature Validation Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 v | May 3, 2024 | 8.8 | 28 | NO | NO |
CVE-2025-2082HIGH Tesla Model 3 VCSEC Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 v | Apr 30, 2025 | 7.5 | 25 | NO | NO |
CVE-2022-42430HIGH This vulnerability allows local attackers to escalate privileges on affected Tesla vehicles. An attacker must first obtain the ability to execute privileged code on the target syst | Mar 29, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-42431HIGH This vulnerability allows local attackers to escalate privileges on affected Tesla vehicles. An attacker must first obtain the ability to execute privileged code on the target syst | Mar 29, 2023 | 7.8 | 24 | NO | NO |
CVE-2019-9977HIGH The renderer process in the entertainment system on Tesla Model 3 vehicles mishandles JIT compilation, which allows attackers to trigger firmware code execution, and display a craf | Mar 24, 2019 | 8.8 | 23 | NO | NO |
CVE-2023-32157HIGH Tesla Model 3 bsa_server BIP Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on af | May 3, 2024 | 7.5 | 22 | NO | NO |
CVE-2022-3093MEDIUM This vulnerability allows physical attackers to execute arbitrary code on affected Tesla vehicles. Authentication is not required to exploit this vulnerability. The specific flaw e | Mar 29, 2023 | 6.4 | 22 | NO | NO |
CVE-2023-32155HIGH Tesla Model 3 bcmdhd Out-Of-Bounds Write Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected Tesla Model 3 vehicl | May 3, 2024 | 7.0 | 20 | NO | NO |
CVE-2022-37709MEDIUM Tesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to Authentication Bypass by spoofing. Tesla Model 3's Phone Key authentication is vulnerable to Ma | Sep 16, 2022 | 5.3 | 20 | NO | NO |
CVE-2020-15912MEDIUM Tesla Model 3 vehicles allow attackers to open a door by leveraging access to a legitimate key card, and then using NFC Relay. NOTE: the vendor has developed Pin2Drive to mitigate | Jul 23, 2020 | 6.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Model 3
Top CWEs
Versions
No cataloged versions.