7.7

CVE-2024-52331

Exploit
ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EcovacsDeebot 900 Firmware Version-
   EcovacsDeebot 900 Version-
EcovacsDeebot N8 Firmware Version-
   EcovacsDeebot N8 Version-
EcovacsDeebot T8 Firmware Version-
   EcovacsDeebot T8 Version-
EcovacsDeebot N9 Firmware Version-
   EcovacsDeebot N9 Version-
EcovacsDeebot T9 Firmware Version-
   EcovacsDeebot T9 Version-
EcovacsDeebot N10 Firmware Version-
   EcovacsDeebot N10 Version-
EcovacsDeebot T10 Firmware Version-
   EcovacsDeebot T10 Version-
EcovacsDeebot X1 Firmware Version-
   EcovacsDeebot X1 Version-
EcovacsDeebot T20 Firmware Version-
   EcovacsDeebot T20 Version-
EcovacsDeebot X2 Firmware Version-
   EcovacsDeebot X2 Version-
EcovacsGoat G1 Firmware Version-
   EcovacsGoat G1 Version-
EcovacsAirbot Z1 Firmware Version-
   EcovacsAirbot Z1 Version-
EcovacsAirbot Ava Firmware Version-
   EcovacsAirbot Ava Version-
EcovacsAirbot Andy Firmware Version-
   EcovacsAirbot Andy Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.287
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
9119a7d8-5eab-497f-8521-727c672e3725 7.7 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
9119a7d8-5eab-497f-8521-727c672e3725 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-1391 Use of Weak Credentials

The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

CWE-327 Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.

CWE-494 Download of Code Without Integrity Check

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.