VulnerabilityAnalyzed
CVE-2024-52327
The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.
MEDIUM 6.0EPSS 0.48%
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.
- CVSS 4.0
- 6.0 MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-603, CWE-807
- Affected
- ecovacs/home
- Source
- 9119a7d8-5eab-497f-8521-727c672e3725
References
- https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdfExploit, Third Party Advisory
- https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdfExploit, Third Party Advisory
- https://www.ecovacs.com/global/userhelp/dsa20241217002Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.