9.5
CVE-2024-52330
- EPSS 0.83%
- Veröffentlicht 23.01.2025 17:15:14
- Zuletzt bearbeitet 23.09.2025 17:48:33
- Quelle 9119a7d8-5eab-497f-8521-727c67
- CVE-Watchlists
- Unerledigt
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ecovacs ≫ Deebot X2 Omni Firmware Version < 1.76.6
Ecovacs ≫ Deebot X2 Combo Firmware Version < 1.81.10
Ecovacs ≫ Deebot X2s Firmware Version < 1.49.0
Ecovacs ≫ Deebot X5 Pro Firmware Version < 1.70.0
Ecovacs ≫ Deebot X5 Pro Plus Firmware Version < 1.38.0
Ecovacs ≫ Deebot X5 Pro Ultra Firmware Version < 1.17.0
Ecovacs ≫ Mate X Firmware Version < 1.44.18
Ecovacs ≫ Deebot X1 Omni Firmware Version < 2.4.41
Ecovacs ≫ Deebot X1 Turbo Firmware Version < 2.4.41
Ecovacs ≫ Deebot X1 Pro Omni Firmware Version < 2.4.41
Ecovacs ≫ Deebot X1 Firmware Version < 1.7.3
Ecovacs ≫ Deebot X1 Plus Firmware Version < 1.7.3
Ecovacs ≫ Deebot X1s Pro Firmware Version < 2.5.31
Ecovacs ≫ Deebot X1s Pro Plus Firmware Version < 1.23.0
Ecovacs ≫ Deebot X1e Omni Firmware Version < 2.4.42
Ecovacs ≫ Deebot T10 Turbo Firmware Version < 1.10.0
Ecovacs ≫ Deebot T10 Plus Firmware Version < 1.7.5
Ecovacs ≫ Deebot T10 Firmware Version < 1.7.5
Ecovacs ≫ Deebot T10 Omni Firmware Version < 1.9.0
Ecovacs ≫ Deebot X2 Pro Firmware Version < 1.76.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.83% | 0.743 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 9119a7d8-5eab-497f-8521-727c672e3725 | 9.5 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| 9119a7d8-5eab-497f-8521-727c672e3725 | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.