ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmower, read the PIN, and reset the anti-theft mechanism.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jan 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmower, read the PIN, and reset the anti-theft mechanism. | |
| Title | ECOVACS lawnmowers cleartext storage of anti-theft PIN | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published: 2025-01-23T16:39:06.903Z
Updated: 2025-02-12T17:12:21.831Z
Reserved: 2024-12-03T00:26:02.380Z
Link: CVE-2024-12079
Updated: 2025-02-12T17:11:41.522Z
Status : Received
Published: 2025-01-23T17:15:13.187
Modified: 2025-01-23T17:15:13.187
Link: CVE-2024-12079
No data.