CVE-2024-11147

EUVD-2024-34389
ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.6 HIGH
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cisa-cgCNA
7.6 HIGH
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
Affected Products (NVD)
VendorProductVersion
ecovacsdeebot_900_firmware
-
ecovacsdeebot_n8_firmware
-
ecovacsdeebot_t8_firmware
-
ecovacsdeebot_n9_firmware
-
ecovacsdeebot_t9_firmware
-
ecovacsdeebot_n10_firmware
-
ecovacsdeebot_t10_firmware
-
ecovacsdeebot_x1_firmware
-
ecovacsdeebot_t20_firmware
-
ecovacsdeebot_x2_firmware
-
ecovacsgoat_g1_firmware
-
ecovacsairbot_z1_firmware
-
ecovacsairbot_ava_firmware
-
ecovacsairbot_andy_firmware
-
𝑥
= Vulnerable software versions