6.3
CVE-2024-12078
- EPSS 0.11%
- Veröffentlicht 23.01.2025 17:15:13
- Zuletzt bearbeitet 23.09.2025 17:45:19
- Quelle 9119a7d8-5eab-497f-8521-727c67
- CVE-Watchlists
- Unerledigt
ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ecovacs ≫ Deebot N10 Firmware Version-
Ecovacs ≫ Deebot T10 Firmware Version-
Ecovacs ≫ Deebot X1 Firmware Version-
Ecovacs ≫ Deebot T20 Firmware Version-
Ecovacs ≫ Deebot X2 Firmware Version-
Ecovacs ≫ Goat G1 Firmware Version-
Ecovacs ≫ Airbot Z1 Firmware Version-
Ecovacs ≫ Airbot Ava Firmware Version-
Ecovacs ≫ Airbot Andy Firmware Version-
Ecovacs ≫ Deebot 900 Firmware Version-
Ecovacs ≫ Deebot N8 Firmware Version-
Ecovacs ≫ Deebot T8 Firmware Version-
Ecovacs ≫ Deebot N9 Firmware Version-
Ecovacs ≫ Deebot T9 Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.292 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 9119a7d8-5eab-497f-8521-727c672e3725 | 5.3 | 0 | 0 |
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| 9119a7d8-5eab-497f-8521-727c672e3725 | 6.3 | 2.8 | 3.4 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
|
CWE-321 Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.