Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7qrq-v84x-p53g

Опубликовано: 23 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.

ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.

EPSS

Процентиль: 9%
0.00031
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-327
CWE-494

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 года назад

ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.

EPSS

Процентиль: 9%
0.00031
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-327
CWE-494