Vulnerability Description
An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character password of *^JEd4W!I that is obfuscated by hiding it within a custom /bin/rc4_crypt binary.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Neatorobotics | Botvac D4 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D4 Connected | - |
| Neatorobotics | Botvac D6 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D6 Connected | - |
| Neatorobotics | Botvac D5 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D5 Connected | - |
| Neatorobotics | Botvac D7 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D7 Connected | - |
| Neatorobotics | Botvac D3 Connected Firmware | 2.2.0 |
| Neatorobotics | Botvac D3 Connected | - |
| Neatorobotics | Botvac 85 Firmware | 1.2.1 |
| Neatorobotics | Botvac 85 Connected | - |
Related Weaknesses (CWE)
References
- https://media.ccc.de/v/2018-124-pinky-brain-are-taking-over-the-world-with-vacuuExploitTechnical DescriptionThird Party Advisory
- https://media.ccc.de/v/2018-124-pinky-brain-are-taking-over-the-world-with-vacuuExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2018-17177?
CVE-2018-17177 is a vulnerability with a CVSS score of 2.4 (LOW). An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick....
How severe is CVE-2018-17177?
CVE-2018-17177 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-17177?
Check the references section above for vendor advisories and patch information. Affected products include: Neatorobotics Botvac D4 Connected Firmware, Neatorobotics Botvac D4 Connected, Neatorobotics Botvac D6 Connected Firmware, Neatorobotics Botvac D6 Connected, Neatorobotics Botvac D5 Connected Firmware.