Table of Contents
Fetching ...

Security Analysis of LTE Connectivity in Connected Cars: A Case Study of Tesla

Evangelos Bitsikas, Jason Veara, Aanjhan Ranganathan

TL;DR

This work addresses the security of LTE connectivity in connected vehicles by conducting a black-box, non-invasive security evaluation on Tesla Model 3 and Cybertruck. A custom LTE experimentation environment combining Amarisoft Callbox, srsRAN, and SDR hardware enables controlled attacks and realistic signaling, revealing critical vulnerabilities such as IMSI catching, rogue base station attachment, insecure fallback loops, and silent processing of SMS and emergency broadcasts. The findings expose systemic gaps in PLMN handling, legacy cipher support, and control-plane security that could disrupt OTA updates, telemetry, and safety services, with implications for UN R155/R156 and ISO 21434 compliance. The authors propose mitigations including stricter PLMN enforcement, rogue-cell detection, safer fallback mechanisms, and a move toward more transparent, testable cellular architectures across OEMs, underscoring the broad, industry-wide impact of commoditized modem components on automotive security.

Abstract

Modern connected vehicles rely on persistent LTE connectivity to enable remote diagnostics, over-the-air (OTA) updates, and critical safety services. While mobile network vulnerabilities are well documented in the smartphone ecosystem, their impact in safety-critical automotive settings remains insufficiently examined. In this work, we conduct a black-box, non-invasive security analysis of LTE connectivity in Tesla vehicles, including the Model 3 and Cybertruck, revealing systemic protocol weaknesses and architectural misconfigurations. We find that Tesla's telematics stack is susceptible to IMSI catching, rogue base station hijacking, and insecure fallback mechanisms that may silently degrade service availability. Furthermore, legacy control-plane configurations allow for silent SMS injection and broadcast message spoofing without driver awareness. These vulnerabilities have implications beyond a single vendor as they challenge core assumptions in regulatory frameworks like ISO/SAE 21434 and UN R155/R156, which require secure, traceable, and resilient telematics for type approval of modern vehicles.

Security Analysis of LTE Connectivity in Connected Cars: A Case Study of Tesla

TL;DR

This work addresses the security of LTE connectivity in connected vehicles by conducting a black-box, non-invasive security evaluation on Tesla Model 3 and Cybertruck. A custom LTE experimentation environment combining Amarisoft Callbox, srsRAN, and SDR hardware enables controlled attacks and realistic signaling, revealing critical vulnerabilities such as IMSI catching, rogue base station attachment, insecure fallback loops, and silent processing of SMS and emergency broadcasts. The findings expose systemic gaps in PLMN handling, legacy cipher support, and control-plane security that could disrupt OTA updates, telemetry, and safety services, with implications for UN R155/R156 and ISO 21434 compliance. The authors propose mitigations including stricter PLMN enforcement, rogue-cell detection, safer fallback mechanisms, and a move toward more transparent, testable cellular architectures across OEMs, underscoring the broad, industry-wide impact of commoditized modem components on automotive security.

Abstract

Modern connected vehicles rely on persistent LTE connectivity to enable remote diagnostics, over-the-air (OTA) updates, and critical safety services. While mobile network vulnerabilities are well documented in the smartphone ecosystem, their impact in safety-critical automotive settings remains insufficiently examined. In this work, we conduct a black-box, non-invasive security analysis of LTE connectivity in Tesla vehicles, including the Model 3 and Cybertruck, revealing systemic protocol weaknesses and architectural misconfigurations. We find that Tesla's telematics stack is susceptible to IMSI catching, rogue base station hijacking, and insecure fallback mechanisms that may silently degrade service availability. Furthermore, legacy control-plane configurations allow for silent SMS injection and broadcast message spoofing without driver awareness. These vulnerabilities have implications beyond a single vendor as they challenge core assumptions in regulatory frameworks like ISO/SAE 21434 and UN R155/R156, which require secure, traceable, and resilient telematics for type approval of modern vehicles.
Paper Structure (18 sections, 17 figures, 4 tables, 1 algorithm)

This paper contains 18 sections, 17 figures, 4 tables, 1 algorithm.

Figures (17)

  • Figure 1: Vital components on a Tesla Model 3.
  • Figure 2: The equipment for the LTE experiments.
  • Figure 3: Examples of LTE attacks: (A) IMSI Catching and (B) False Base Stations.
  • Figure 4: Example of IMSI catching against Tesla Model 3.
  • Figure 5: Tesla services failing during the FBS attacks.
  • ...and 12 more figures