A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not checked at all.
References
Link | Resource |
---|---|
https://media.ccc.de/v/2018-124-pinky-brain-are-taking-over-the-world-with-vacuum-cleaners | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-03T16:22:10
Updated: 2022-10-03T16:22:10
Reserved: 2022-10-03T00:00:00
Link: CVE-2018-17176
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-09-18T18:29:08.897
Modified: 2020-08-24T17:37:01.140
Link: CVE-2018-17176
JSON object: View
Redhat Information
No data.
CWE