SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-17177

An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices.

LOW 2.4EPSS 0.17%

Does this matter?

Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character password of *^JEd4W!I that is obfuscated by hiding it within a custom /bin/rc4_crypt binary.

CVSS 3.1
2.4 LOWCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.17% probability · 7th percentile
CISA KEV
Not listed
Weakness
CWE-326
Affected
neatorobotics/botvac d4 connected firmware · neatorobotics/botvac d6 connected firmware · neatorobotics/botvac d5 connected firmware · neatorobotics/botvac d7 connected firmware · neatorobotics/botvac d3 connected firmware · neatorobotics/botvac 85 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.