LOW · 2.3

CVE-2024-52328

ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that u...

Vulnerability Description

ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.

CVSS Score

2.3

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
EcovacsDeebot N8 Firmware-
EcovacsDeebot N8-
EcovacsDeebot 900 Firmware-
EcovacsDeebot 900-
EcovacsDeebot T8 Firmware-
EcovacsDeebot T8-
EcovacsDeebot N9 Firmware-
EcovacsDeebot N9-
EcovacsDeebot T9 Firmware-
EcovacsDeebot T9-
EcovacsDeebot N10 Firmware-
EcovacsDeebot N10-
EcovacsDeebot T10 Firmware-
EcovacsDeebot T10-
EcovacsDeebot X1 Firmware-
EcovacsDeebot X1-
EcovacsDeebot T20 Firmware-
EcovacsDeebot T20-
EcovacsDeebot X2 Firmware-
EcovacsDeebot X2-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-52328?

CVE-2024-52328 is a vulnerability with a CVSS score of 2.3 (LOW). ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that u...

How severe is CVE-2024-52328?

CVE-2024-52328 has been rated LOW with a CVSS base score of 2.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-52328?

Check the references section above for vendor advisories and patch information. Affected products include: Ecovacs Deebot N8 Firmware, Ecovacs Deebot N8, Ecovacs Deebot 900 Firmware, Ecovacs Deebot 900, Ecovacs Deebot T8 Firmware.