CVE-2024-52328

ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.3 LOW
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
cisa-cgCNA
2.3 LOW
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
VendorProductVersion
ecovacsdeebot_n8_firmware
-
ecovacsdeebot_900_firmware
-
ecovacsdeebot_t8_firmware
-
ecovacsdeebot_n9_firmware
-
ecovacsdeebot_t9_firmware
-
ecovacsdeebot_n10_firmware
-
ecovacsdeebot_t10_firmware
-
ecovacsdeebot_x1_firmware
-
ecovacsdeebot_t20_firmware
-
ecovacsdeebot_x2_firmware
-
ecovacsgoat_g1_firmware
-
ecovacsairbot_z1_firmware
-
ecovacsairbot_ava_firmware
-
ecovacsairbot_andy_firmware
-
𝑥
= Vulnerable software versions