CVE-2018-11567
Last modified
CVE-2018-11567 is a vulnerability of currently unknown severity. Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt feature is designed so that if Alexa does not receive an input within 8 seconds, the device can speak a reprompt, then wait an additional 8 seconds for input; if the user still does not respond, the microphone is then turned off. EPSS estimates a 1.09% chance of exploitation in the next 30 days.
Description
Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt feature is designed so that if Alexa does not receive an input within 8 seconds, the device can speak a reprompt, then wait an additional 8 seconds for input; if the user still does not respond, the microphone is then turned off. The vulnerability involves empty output-speech reprompts, custom wildcard ("gibberish") input slots, and logging of detected speech. If a maliciously designed skill is installed, an attacker could obtain transcripts of speech not intended for Alexa to process, but simply spoken within the device's hearing range. NOTE: The vendor states "Customer trust is important to us and we take security and privacy seriously. We have put mitigations in place for detecting this type of skill behavior and reject or suppress those skills when we do. Customers do not need to take any action for these mitigations to work.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Amazon | Echo Show Firmware | < 2018-04-27 |
| Amazon | Echo Plus Firmware | < 2018-04-27 |
| Amazon | Echo Dot Firmware | < 2018-04-27 |
| Amazon | Echo Spot Firmware | < 2018-04-27 |
| Amazon | Echo Firmware | < 2018-04-27 |
References
- https://info.checkmarx.com/hubfs/Amazon_Echo_Research.pdfExploit, Third Party Advisory
- https://www.checkmarx.com/2018/04/25/eavesdropping-with-amazon-alexa/Third Party Advisory
- https://www.wired.com/story/amazon-echo-alexa-skill-spying/Press/Media Coverage, Third Party Advisory
- https://www.yahoo.com/news/amazon-alexa-bug-let-hackers-104609600.htmlPress/Media Coverage, Third Party Advisory
- https://info.checkmarx.com/hubfs/Amazon_Echo_Research.pdfExploit, Third Party Advisory
- https://www.checkmarx.com/2018/04/25/eavesdropping-with-amazon-alexa/Third Party Advisory
- https://www.wired.com/story/amazon-echo-alexa-skill-spying/Press/Media Coverage, Third Party Advisory
- https://www.yahoo.com/news/amazon-alexa-bug-let-hackers-104609600.htmlPress/Media Coverage, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-11567?
How severe is CVE-2018-11567?
How do I fix CVE-2018-11567?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-11560The webService binary on Insteon HD IP Camera White 2864-222…9.8
- CVE-2018-11561An integer overflow in the unprotected distributeToken funct…7.5
- CVE-2018-11562An issue was discovered in MISP 2.4.91. A vulnerability in a…
- CVE-2018-11563An issue was discovered in Open Ticket Request System (OTRS)…4.6
- CVE-2018-11564Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a u…
- CVE-2018-11565Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.…
- CVE-2018-11568Reflected XSS is possible in the GamePlan theme through 1.5.…
- CVE-2018-11569Controller/ListController.php in Eventum 3.5.0 is vulnerable…
- CVE-2018-1157Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to …
- CVE-2018-11571ClipperCMS 1.3.3 allows Session Fixation.
- CVE-2018-11572ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Mo…
- CVE-2018-11574Improper input validation together with an integer overflow …9.8
Are you affected by CVE-2018-11567?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
