Vulnerability Description
Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks. NOTE: reportedly, there were vendor marketing statements about safely removing personal content via a factory reset. Also, the vendor has reportedly indicated that they are working on mitigations.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amazon | Echo Dot Firmware | <= 2021-07-02 |
| Amazon | Echo Dot | - |
References
- https://arstechnica.com/gadgets/2021/07/passwords-in-amazon-echo-dots-live-on-evThird Party Advisory
- https://dl.acm.org/doi/pdf/10.1145/3448300.3467820Technical DescriptionThird Party Advisory
- https://news.ycombinator.com/item?id=27943730Third Party Advisory
- https://www.cpomagazine.com/data-privacy/is-it-possible-to-make-iot-devices-privThird Party Advisory
- https://arstechnica.com/gadgets/2021/07/passwords-in-amazon-echo-dots-live-on-evThird Party Advisory
- https://dl.acm.org/doi/pdf/10.1145/3448300.3467820Technical DescriptionThird Party Advisory
- https://news.ycombinator.com/item?id=27943730Third Party Advisory
- https://www.cpomagazine.com/data-privacy/is-it-possible-to-make-iot-devices-privThird Party Advisory
FAQ
What is CVE-2021-37436?
CVE-2021-37436 is a vulnerability with a CVSS score of 4.2 (MEDIUM). Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and s...
How severe is CVE-2021-37436?
CVE-2021-37436 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-37436?
Check the references section above for vendor advisories and patch information. Affected products include: Amazon Echo Dot Firmware, Amazon Echo Dot.