Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92x4-p455-q3x7

Опубликовано: 23 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 1.8
CVSS3: 2.3

Описание

ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.

ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.

EPSS

Процентиль: 11%
0.00037
Низкий

1.8 Low

CVSS4

2.3 Low

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 2.3
nvd
около 1 года назад

ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.

EPSS

Процентиль: 11%
0.00037
Низкий

1.8 Low

CVSS4

2.3 Low

CVSS3

Дефекты

CWE-732