CVE-2024-52329
CVE-2024-52329
9.5
CriticalPublished:
Last updated:
Source:9119a7d8-5eab-497f-8521-727c672e3725
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- Present
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- None
- Confidentiality (Subsequent)
- High
- Integrity (Subsequent)
- High
- Availability (Subsequent)
- High
Description
ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens.
References
9119a7d8-5eab-497f-8521-727c672e3725
https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf9119a7d8-5eab-497f-8521-727c672e3725
https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdf9119a7d8-5eab-497f-8521-727c672e3725
https://www.ecovacs.com/global/userhelp/dsa20241217001