Welcome to Tesla Motors Club
Discuss Tesla's Model S, Model 3, Model X, Model Y, Cybertruck, Roadster and More.
Register

Security Issue? Log4j

This site may earn commission on affiliate links.
The IT world is kind of on fire today with a security vulnerability in a common software library.


The reason I'm posting here is because Tesla might be impacted. Scroll down to Tesla to see a photo
 
  • Informative
Reactions: Tdreamer
MicrosoftTeams-image (8).jpg
 
Tesla already mitigated this, but one of the ways it could be triggered was that Tesla logs the name of the phone the car is connected to, so you could have renamed your phone to the JNDI string. Also worked with the car's name and probably also with profile names and key names. The thing is, you had to have access to the unlocked car to do any of this stuff, and then the thing you are hacking is not the car, but Tesla's server.

If damage was done, it was already done and someone has a lot of data about our cars at least from reading the log files.

Where this bug is going to be massive is in mid-sized credit unions with local yocal IT support. They will stay vulnerable for months and have improper sandboxing so attackers can find ways into actual banking data.