Physical/safety
DEVICE_CONTROL_SAFETY
Vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:1/EC:3/EX:1/PH:4/DP:3/AT:3/CH:4/SR:3/SX:3/OR:2/EV:3/LS:PATCH_AVAILABLE CPATH-2026-0019 · DRONE AV
DEVICE_CONTROL_SAFETY Physical/safety · Evidence EV:3 (reproduced / report-backed) · Liveness PATCH_AVAILABLE | CPATH ID | CPATH-2026-0019 |
| CVE(s) | CVE-2023-32156 |
| Device / class | Tesla Model 3 Gateway Firmware Signature-Bypass / TOCTTOU Code Execution (CVE-2023-32156) (DRONE AV) |
| Vendor | Tesla |
| Dominant consequence | DEVICE_CONTROL_SAFETY (Physical/safety) |
| Paths verdict | CRITICAL (worst of 2 paths) |
| Published baseline | v3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVDv3.0 9 CRITICAL CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H · ZDI via NVD |
| Baseline relationship | ◀▶ comparable |
| Consequence dimension(s) | #1 #2 (what these mean) |
| Scored | 2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional |
| Baseline confidence | high |
Consequence Paths
Physical/safety
DEVICE_CONTROL_SAFETYCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:1/EC:3/EX:1/PH:4/DP:3/AT:3/CH:4/SR:3/SX:3/OR:2/EV:3/LS:PATCH_AVAILABLE authority
FIRMWARE_TRUST_ROOTCPATH:1.0-candidate/TT:FIRMWARE_TRUST_ROOT/RE:1/EC:3/EX:1/PH:4/DP:3/AT:4/CH:4/SR:4/SX:3/OR:3/EV:3/LS:PATCH_AVAILABLE CFSE Consequence Paths assesses Tesla Model 3 Gateway Firmware Signature-Bypass / TOCTTOU Code Execution (CVE-2023-32156) at CRITICAL — the worst of 2 risk paths (safety, authority). The dominant consequence is influence over a safety-relevant actuation.
Tesla Model 3 Gateway Firmware Signature-Bypass / TOCTTOU Code Execution (CVE-2023-32156). Reported attack vector: Adjacent network (requires prior code execution on infotainment to reach Gateway).
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → CRITICALCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:1/EC:3/EX:1/PH:4/DP:3/AT:3/CH:4/SR:3/SX:3/OR:2/EV:3/LS:PATCH_AVAILABLE
Exposure EX=1 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · caps low-exposure cap → assessed CRITICAL.
FIRMWARE_TRUST_ROOT → CRITICALCPATH:1.0-candidate/TT:FIRMWARE_TRUST_ROOT/RE:1/EC:3/EX:1/PH:4/DP:3/AT:4/CH:4/SR:4/SX:3/OR:3/EV:3/LS:PATCH_AVAILABLE
Exposure EX=1 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · caps low-exposure cap → assessed CRITICAL.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — NVDCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H — ZDI via NVDThe published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.
CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0019 (“Tesla Model 3 Gateway Firmware Signature-Bypass / TOCTTOU Code Execution (CVE-2023-32156)”), paths.cfse.ai/CPATH-2026-0019 (published 2026-06-03).