ZeroHour

CVE-2018-17176

PoC
CVSS 3.0
7.5 high
EPSS
1%p61
Published
()
Modified
Description

A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not checked at all.

Vendors
neatorobotics
Products
botvac d4 connected firmware, botvac d6 connected firmware, botvac d7 connected firmware
Weakness
CWE-294
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.