Vulnerability Description
ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmower, read the PIN, and reset the anti-theft mechanism.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ecovacs | Deebot 900 Firmware | - |
| Ecovacs | Deebot 900 | - |
| Ecovacs | Deebot N8 Firmware | - |
| Ecovacs | Deebot N8 | - |
| Ecovacs | Deebot T8 Firmware | - |
| Ecovacs | Deebot T8 | - |
| Ecovacs | Deebot N9 Firmware | - |
| Ecovacs | Deebot N9 | - |
| Ecovacs | Deebot T9 Firmware | - |
| Ecovacs | Deebot T9 | - |
| Ecovacs | Deebot N10 Firmware | - |
| Ecovacs | Deebot N10 | - |
| Ecovacs | Deebot T10 Firmware | - |
| Ecovacs | Deebot T10 | - |
| Ecovacs | Deebot X1 Firmware | - |
| Ecovacs | Deebot X1 | - |
| Ecovacs | Deebot T20 Firmware | - |
| Ecovacs | Deebot T20 | - |
| Ecovacs | Deebot X2 Firmware | - |
| Ecovacs | Deebot X2 | - |
Related Weaknesses (CWE)
References
- https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdfExploitThird Party Advisory
FAQ
What is CVE-2024-12079?
CVE-2024-12079 is a vulnerability with a CVSS score of 3.3 (LOW). ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmower, read the PIN, and reset the anti-theft mechanism.
How severe is CVE-2024-12079?
CVE-2024-12079 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-12079?
Check the references section above for vendor advisories and patch information. Affected products include: Ecovacs Deebot 900 Firmware, Ecovacs Deebot 900, Ecovacs Deebot N8 Firmware, Ecovacs Deebot N8, Ecovacs Deebot T8 Firmware.