CVE Vulnerabilities

CVE-2023-29389

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Published: Apr 05, 2023 | Modified: Apr 14, 2023
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Toyota RAV4 2021 vehicles automatically trust messages from other ECUs on a CAN bus, which allows physically proximate attackers to drive a vehicle by accessing the control CAN bus after pulling the bumper away and reaching the headlight connector, and then sending forged Key is validated messages via CAN Injection, as exploited in the wild in (for example) July 2022.

Weakness

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Affected Software

Name Vendor Start Version End Version
Rav4_firmware Toyota 2021 (including) 2021 (including)

Potential Mitigations

References