| CVE ID | CVE-2022-3093 | 
| CVSS SCORE | 7.6, AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H | 
| AFFECTED VENDORS | 
                            
                            
                            Tesla | 
                    
| AFFECTED PRODUCTS | 
                            
                            
                            Model 3 | 
                    
| VULNERABILITY DETAILS | 
                             This vulnerability allows physical attackers to execute arbitrary code on affected Tesla vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ice_updater update mechanism. The issue results from the lack of proper validation of user-supplied firmware. An attacker can leverage this vulnerability to execute code in the context of root.  | 
                    
| ADDITIONAL DETAILS | 
                            
                            
                            
                             Issue was fixed starting in Tesla’s 2022.16.0.3 release.  | 
                    
| DISCLOSURE TIMELINE | 
                            
  | 
                    
| CREDIT | @Jedar_LZ |