Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m5xh-jxq3-g8gc

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 2.4

Описание

An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character password of *^JEd4W!I that is obfuscated by hiding it within a custom /bin/rc4_crypt binary.

An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character password of *^JEd4W!I that is obfuscated by hiding it within a custom /bin/rc4_crypt binary.

EPSS

Процентиль: 4%
0.00019
Низкий

2.4 Low

CVSS3

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 2.4
nvd
больше 7 лет назад

An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character password of *^JEd4W!I that is obfuscated by hiding it within a custom /bin/rc4_crypt binary.

EPSS

Процентиль: 4%
0.00019
Низкий

2.4 Low

CVSS3

Дефекты

CWE-326