CVE-2018-20785
Last modified
CVE-2018-20785 is a vulnerability of currently unknown severity. Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. Secure boot can be bypassed by starting with certain commands to the USB serial port. Although a power cycle occurs, this does not completely reset the chip: memory contents are still in place. Also, it restarts into a boot menu that enables XMODEM upload and execution of an unsigned QNX IFS system image, thereby completing the bypass of secure boot. Moreover, the attacker can craft custom IFS data and write it to unused memory to extract all memory contents that had previously been present. This includes the original firmware and sensitive information such as Wi-Fi credentials.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Neatorobotics | Botvac D4 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D6 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D5 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D7 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D3 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D3 Pro Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac Connected Firmware | 2.2.0 |
References
- https://media.ccc.de/v/2018-124-pinky-brain-are-taking-over-the-world-with-vacuum-cleaners#t=745Exploit, Third Party Advisory
- https://media.ccc.de/v/2018-124-pinky-brain-are-taking-over-the-world-with-vacuum-cleaners#t=745Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20785?
How severe is CVE-2018-20785?
How do I fix CVE-2018-20785?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-2078Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-20780Traq 3.7.1 allows admin/users/new CSRF to create an admin ac…
- CVE-2018-20781In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the …7.8
- CVE-2018-20782The GloBee plugin before 1.1.2 for WooCommerce mishandles IP…
- CVE-2018-20783In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25…
- CVE-2018-20784In the Linux kernel before 4.20.2, kernel/sched/fair.c misha…9.8
- CVE-2018-20786libvterm through 0+bzr726, as used in Vim and other products…
- CVE-2018-20787The ft5x46 touchscreen driver for custom Linux kernels on th…
- CVE-2018-20788drivers/leds/leds-aw2023.c in the led driver for custom Linu…
- CVE-2018-20789tecrail Responsive FileManager 9.13.4 allows remote attacker…
- CVE-2018-2079Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-20790tecrail Responsive FileManager 9.13.4 allows remote attacker…
Are you affected by CVE-2018-20785?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
