CVE-2024-52328 – ECOVACS Robot Camera File Deletion Arbitrary File Write

The following table lists the changes that have been made to the
CVE-2024-52328 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 9119a7d8-5eab-497f-8521-727c672e3725

    Jan. 23, 2025

    Action Type Old Value New Value
    Added Description ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.
    Added CVSS V4.0 AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
    Added CWE CWE-732
    Added Reference https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf
    Added Reference https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdf
Share the Post:

Related Posts