Lucene search

K
cvelistMitreCVELIST:CVE-2018-17176
HistorySep 18, 2018 - 6:00 p.m.

CVE-2018-17176

2018-09-1818:00:00
mitre
www.cve.org
1
neato botvac
authentication
cleartext
webserver
security flaw
timestamps

EPSS

0.001

Percentile

44.9%

A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not checked at all.

EPSS

0.001

Percentile

44.9%

Related for CVELIST:CVE-2018-17176