CVE-2024-52328

EUVD-2024-46257
ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.3 LOW
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
cisa-cgCNA
2.3 LOW
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Affected Products (NVD)
VendorProductVersion
ecovacsdeebot_n8_firmware
-
ecovacsdeebot_900_firmware
-
ecovacsdeebot_t8_firmware
-
ecovacsdeebot_n9_firmware
-
ecovacsdeebot_t9_firmware
-
ecovacsdeebot_n10_firmware
-
ecovacsdeebot_t10_firmware
-
ecovacsdeebot_x1_firmware
-
ecovacsdeebot_t20_firmware
-
ecovacsdeebot_x2_firmware
-
ecovacsgoat_g1_firmware
-
ecovacsairbot_z1_firmware
-
ecovacsairbot_ava_firmware
-
ecovacsairbot_andy_firmware
-
𝑥
= Vulnerable software versions