{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-21T22:59:17.028","vulnerabilities":[{"cve":{"id":"CVE-2024-6030","sourceIdentifier":"zdi-disclosures@trendmicro.com","published":"2025-04-30T20:15:21.030","lastModified":"2025-08-12T15:16:26.713","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code within the sandbox on the target system in order to exploit this vulnerability.\n \nThe specific flaw exists within the oFono process. The process allows an attacker to modify interfaces. An attacker can leverage this vulnerability to bypass the iptables network sandbox. Was ZDI-CAN-23200."},{"lang":"es","value":"Vulnerabilidad de escape del entorno de pruebas de oFono con privilegios innecesarios en el Tesla Model S. Esta vulnerabilidad permite a atacantes locales escapar del entorno de pruebas en los vehículos Tesla Model S afectados. Para explotar esta vulnerabilidad, un atacante debe primero ejecutar código dentro del entorno de pruebas en el sistema objetivo. La falla específica se encuentra en el proceso oFono, que permite a un atacante modificar interfaces. Un atacante puede aprovechar esta vulnerabilidad para eludir el entorno de pruebas de red de iptables. Anteriormente, se denominaba ZDI-CAN-23200."}],"metrics":{"cvssMetricV30":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.0,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.0,"impactScore":5.9}]},"weaknesses":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","description":[{"lang":"en","value":"CWE-250"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tesla:model_s_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2024.8","matchCriteriaId":"D1F9CBB6-013F-43C4-B01D-D8CBE1623F4E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tesla:model_s:-:*:*:*:*:*:*:*","matchCriteriaId":"8D28E699-B843-4641-9BA6-406D88231E7C"}]}]}],"references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-25-263/","source":"zdi-disclosures@trendmicro.com","tags":["Third Party Advisory"]}]}}]}