Lucene search

K
cveMitreCVE-2018-17177
HistorySep 18, 2018 - 6:29 p.m.

CVE-2018-17177

2018-09-1818:29:09
CWE-326
mitre
web.nvd.nist.gov
24
6
cve-2018-17177
neato botvac
connected 2.2.0
botvac 85 1.2.1
static encryption
rc4
usb
security issue

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

2.4

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

4.2

Confidence

High

EPSS

0.002

Percentile

58.0%

An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called “black box” logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character password of *^JEd4W!I that is obfuscated by hiding it within a custom /bin/rc4_crypt binary.

Affected configurations

Nvd
Node
neatoroboticsbotvac_d4_connectedMatch-
AND
neatoroboticsbotvac_d4_connected_firmwareMatch2.2.0
Node
neatoroboticsbotvac_d6_connectedMatch-
AND
neatoroboticsbotvac_d6_connected_firmwareMatch2.2.0
Node
neatoroboticsbotvac_d5_connectedMatch-
AND
neatoroboticsbotvac_d5_connected_firmwareMatch2.2.0
Node
neatoroboticsbotvac_d7_connectedMatch-
AND
neatoroboticsbotvac_d7_connected_firmwareMatch2.2.0
Node
neatoroboticsbotvac_d3_connectedMatch-
AND
neatoroboticsbotvac_d3_connected_firmwareMatch2.2.0
Node
neatoroboticsbotvac_85_connectedMatch-
AND
neatoroboticsbotvac_85_firmwareMatch1.2.1
VendorProductVersionCPE
neatoroboticsbotvac_d4_connected-cpe:2.3:h:neatorobotics:botvac_d4_connected:-:*:*:*:*:*:*:*
neatoroboticsbotvac_d4_connected_firmware2.2.0cpe:2.3:o:neatorobotics:botvac_d4_connected_firmware:2.2.0:*:*:*:*:*:*:*
neatoroboticsbotvac_d6_connected-cpe:2.3:h:neatorobotics:botvac_d6_connected:-:*:*:*:*:*:*:*
neatoroboticsbotvac_d6_connected_firmware2.2.0cpe:2.3:o:neatorobotics:botvac_d6_connected_firmware:2.2.0:*:*:*:*:*:*:*
neatoroboticsbotvac_d5_connected-cpe:2.3:h:neatorobotics:botvac_d5_connected:-:*:*:*:*:*:*:*
neatoroboticsbotvac_d5_connected_firmware2.2.0cpe:2.3:o:neatorobotics:botvac_d5_connected_firmware:2.2.0:*:*:*:*:*:*:*
neatoroboticsbotvac_d7_connected-cpe:2.3:h:neatorobotics:botvac_d7_connected:-:*:*:*:*:*:*:*
neatoroboticsbotvac_d7_connected_firmware2.2.0cpe:2.3:o:neatorobotics:botvac_d7_connected_firmware:2.2.0:*:*:*:*:*:*:*
neatoroboticsbotvac_d3_connected-cpe:2.3:h:neatorobotics:botvac_d3_connected:-:*:*:*:*:*:*:*
neatoroboticsbotvac_d3_connected_firmware2.2.0cpe:2.3:o:neatorobotics:botvac_d3_connected_firmware:2.2.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

Social References

More

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

2.4

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

4.2

Confidence

High

EPSS

0.002

Percentile

58.0%

Related for CVE-2018-17177