CVE-2024-52327 – ECOVACS Cloud Service Authenticated Bypass Vulnerability

The following table lists the changes that have been made to the
CVE-2024-52327 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 9119a7d8-5eab-497f-8521-727c672e3725

    Jan. 23, 2025

    Action Type Old Value New Value
    Added Description The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed.
    Added CVSS V4.0 AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
    Added CWE CWE-603
    Added CWE CWE-807
    Added Reference https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf
    Added Reference https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdf
    Added Reference https://www.ecovacs.com/global/userhelp/dsa20241217002
Share the Post:

Related Posts