ZeroHour

CVE-2024-52330

PoC ×2
CVSS 4.0
9.5 critical
EPSS
<1%p28
Published
()
Modified
Description

ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.

Vendors
ecovacs
Products
deebot x2 omni firmware, deebot x2 combo firmware, deebot x2s firmware, deebot x5 pro firmware, deebot x5 pro plus firmware, deebot x5 pro ultra firmware, mate x firmware, deebot x1 omni firmware, deebot x1 turbo firmware, deebot x1 pro omni firmware, deebot x1 firmware, deebot x1 plus firmware
Weakness
CWE-295
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.