Toyota RAV4 2021 vehicles automatically trust messages from other ECUs on a CAN bus, which allows physically proximate attackers to drive a vehicle by accessing the control CAN bus after pulling the bumper away and reaching the headlight connector, and then sending forged "Key is validated" messages via CAN Injection, as exploited in the wild in (for example) July 2022.
History

Wed, 12 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-04-05T00:00:00.000Z

Updated: 2025-02-12T16:12:07.270Z

Reserved: 2023-04-05T00:00:00.000Z

Link: CVE-2023-29389

cve-icon Vulnrichment

Updated: 2024-08-02T14:07:45.988Z

cve-icon NVD

Status : Modified

Published: 2023-04-05T16:15:08.100

Modified: 2025-02-12T16:15:38.110

Link: CVE-2023-29389

cve-icon Redhat

No data.