Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:o:tesla:model_x_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F6172D4-78B1-451A-A1CD-D83E8514C3F6", "versionEndExcluding": "2020-11-23", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:h:tesla:model_x:-:*:*:*:*:*:*:*", "matchCriteriaId": "C550FF8A-58ED-4265-B33F-10AFDEA95519", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}], "descriptions": [{"lang": "en", "value": "Tesla Model X vehicles before 2020-11-23 have key fobs that rely on five VIN digits for the authentication needed for a body control module (BCM) to initiate a Bluetooth wake-up action. (The full VIN is visible from outside the vehicle.)"}, {"lang": "es", "value": "Los veh\u00edculos Tesla Model X anterior al 23-11-2020 tienen llaveros que dependen de cinco d\u00edgitos VIN para la autenticaci\u00f3n necesaria para que un m\u00f3dulo de control de carrocer\u00eda (BCM) inicie una acci\u00f3n de activaci\u00f3n de Bluetooth. (El VIN completo es visible desde el exterior del veh\u00edculo)"}], "id": "CVE-2020-29439", "lastModified": "2024-11-21T05:24:00.360", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "LOW", "cvssData": {"accessComplexity": "LOW", "accessVector": "LOCAL", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 2.1, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N", "version": "2.0"}, "exploitabilityScore": 3.9, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}], "cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "PHYSICAL", "availabilityImpact": "NONE", "baseScore": 4.6, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1"}, "exploitabilityScore": 0.9, "impactScore": 3.6, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2020-11-30T22:15:10.963", "references": [{"source": "cve@mitre.org", "tags": ["Exploit", "Press/Media Coverage", "Third Party Advisory"], "url": "https://www.wired.com/story/tesla-model-x-hack-bluetooth/"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Exploit", "Press/Media Coverage", "Third Party Advisory"], "url": "https://www.wired.com/story/tesla-model-x-hack-bluetooth/"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "NVD-CWE-noinfo"}], "source": "nvd@nist.gov", "type": "Primary"}]}