Tesla values the work done by security researchers in improving the security of our products and service offerings. We are committed to working with this community to verify, reproduce, and respond to legitimate reported vulnerabilities. We encourage the community to participate in our responsible reporting process.
For vehicle or energy products
While we use Bugcrowd as a platform for rewarding all issues, please report vehicle and product related issues directly to vulnerabilityreporting@tesla.com, using our GPG key to encrypt reports containing sensitive information.
Third-party bugs
If issues reported to our bug bounty program affect a third-party library, external project, or another vendor, Tesla reserves the right to forward details of the issue to that party without further discussion with the researcher. We will do our best to coordinate and communicate with researchers through this process.
Responsible Disclosure Guidelines
We will investigate legitimate reports and make every effort to quickly correct any vulnerability. To encourage responsible reporting, we will not take legal action against you nor ask law enforcement to investigate you providing you comply with the following Responsible Disclosure Guidelines:
For the avoidance of doubt,
This program follows Bugcrowd’s standard disclosure terms.
For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.
This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.
We support the open publication of security research. We do ask that you give us a heads-up before any publication so we can do a final sync-up and check.
Scope Type | Scope Name |
---|---|
android_application | Official Tesla Android apps |
hardware | A hardware product that you own or are authorized to test against (Vehicle/PowerWall/etc.) |
ios_application | Official Tesla iOS apps |
undefined | Any host verified to be owned by Tesla Motors Inc. (domains/IP space/etc.) |
web_application | *.tesla.com |
web_application | *.tesla.cn |
web_application | *.teslamotors.com |
web_application | *.tesla.services |
web_application | *.teslainsuranceservices.com |
web_application | *.solarcity.com |
Scope Type | Scope Name |
---|---|
undefined | energysupport.tesla.com (you can report vulnerabilities to bugbounty.zoho.com) |
web_application | Any domains from acquisitions, such as maxwell.com |
web_application | employeefeedback.tesla.com |
web_application | engage.tesla.com |
web_application | feedback.tesla.com |
web_application | feedback.teslamotors.com |
web_application | ir.teslamotors.com |
web_application | ir.tesla.com |
web_application | mkto.teslamotors.com |
web_application | shop.eu.teslamotors.com |
web_application | Any other third-party websites hosted by non-Tesla entities |
This program crawled on the 2018-03-22 is sorted as bounty.
FireBounty © 2015-2024