CVE-2018-20785
Last modified
CVE-2018-20785 is a vulnerability of currently unknown severity. Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. Secure boot can be bypassed by starting with certain commands to the USB serial port. Although a power cycle occurs, this does not completely reset the chip: memory contents are still in place. Also, it restarts into a boot menu that enables XMODEM upload and execution of an unsigned QNX IFS system image, thereby completing the bypass of secure boot. Moreover, the attacker can craft custom IFS data and write it to unused memory to extract all memory contents that had previously been present. This includes the original firmware and sensitive information such as Wi-Fi credentials.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Neatorobotics | Botvac D4 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D6 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D5 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D7 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D3 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D3 Pro Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac Connected Firmware | 2.2.0 |
References
- https://media.ccc.de/v/2018-124-pinky-brain-are-taking-over-the-world-with-vacuum-cleaners#t=745Exploit, Third Party Advisory
- https://media.ccc.de/v/2018-124-pinky-brain-are-taking-over-the-world-with-vacuum-cleaners#t=745Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20785?
How severe is CVE-2018-20785?
How do I fix CVE-2018-20785?
Are you affected by CVE-2018-20785?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
