Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3jw-m3f7-54qm

Опубликовано: 23 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7
CVSS3: 7.6

Описание

ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.

ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.

EPSS

Процентиль: 31%
0.0012
Низкий

7 High

CVSS4

7.6 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 7.6
nvd
около 1 года назад

ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.

EPSS

Процентиль: 31%
0.0012
Низкий

7 High

CVSS4

7.6 High

CVSS3

Дефекты

CWE-798