ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jan 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot. | |
| Title | ECOVACS lawnmowers and vacuums deterministic firmware encryption key | |
| Weaknesses | CWE-1391 CWE-494 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published: 2025-01-23T16:37:31.290Z
Updated: 2025-02-12T20:41:28.822Z
Reserved: 2024-11-08T01:06:02.405Z
Link: CVE-2024-52331
Updated: 2025-02-12T20:35:29.355Z
Status : Received
Published: 2025-01-23T17:15:14.563
Modified: 2025-01-23T17:15:14.563
Link: CVE-2024-52331
No data.