CVE-2018-17176
Last modified
CVE-2018-17176 is a vulnerability of currently unknown severity. A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not checked at all.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Neatorobotics | Botvac D4 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D6 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D7 Connected Firmware | 2.2.0 |
References
- https://media.ccc.de/v/2018-124-pinky-brain-are-taking-over-the-world-with-vacuum-cleanersExploit, Third Party Advisory
- https://media.ccc.de/v/2018-124-pinky-brain-are-taking-over-the-world-with-vacuum-cleanersExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-17176?
How severe is CVE-2018-17176?
How do I fix CVE-2018-17176?
Are you affected by CVE-2018-17176?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
