VulnerabilityModified
CVE-2018-17177
An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices.
LOW 2.4EPSS 0.17%
Does this matter?
Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character password of *^JEd4W!I that is obfuscated by hiding it within a custom /bin/rc4_crypt binary.
- CVSS 3.1
- 2.4 LOWCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.17% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-326
- Affected
- neatorobotics/botvac d4 connected firmware · neatorobotics/botvac d6 connected firmware · neatorobotics/botvac d5 connected firmware · neatorobotics/botvac d7 connected firmware · neatorobotics/botvac d3 connected firmware · neatorobotics/botvac 85 firmware
- Source
- cve@mitre.org
References
- https://media.ccc.de/v/2018-124-pinky-brain-are-taking-over-the-world-with-vacuum-cleanersExploit, Technical Description, Third Party Advisory
- https://media.ccc.de/v/2018-124-pinky-brain-are-taking-over-the-world-with-vacuum-cleanersExploit, Technical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.