CVE-2018-20785
- EPSS 0.08%
- Veröffentlicht 23.02.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:10
Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. Secure boot can be bypassed by starting with certain commands to the USB ...
CVE-2018-17177
- EPSS 0.02%
- Veröffentlicht 18.09.2018 18:29:09
- Zuletzt bearbeitet 21.11.2024 03:54:01
An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character p...
CVE-2018-17178
- EPSS 0.1%
- Veröffentlicht 18.09.2018 18:29:09
- Zuletzt bearbeitet 21.11.2024 03:54:01
An issue was discovered on Neato Botvac Connected 2.2.0 devices. They execute unauthenticated manual drive commands (sent to /bin/webserver on port 8081) if they already have an active session. Commands like forward, back, arc-left, arc-right, pivot-...
CVE-2018-17176
- EPSS 0.31%
- Veröffentlicht 18.09.2018 18:29:08
- Zuletzt bearbeitet 21.11.2024 03:54:01
A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no n...