HIGH · 7.4

CVE-2024-52330

ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.

Vulnerability Description

ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.

CVSS Score

7.4

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
EcovacsDeebot X2 Omni Firmware< 1.76.6
EcovacsDeebot X2 Omni-
EcovacsDeebot X2 Combo Firmware< 1.81.10
EcovacsDeebot X2 Combo-
EcovacsDeebot X2S Firmware< 1.49.0
EcovacsDeebot X2S-
EcovacsDeebot X5 Pro Firmware< 1.70.0
EcovacsDeebot X5 Pro-
EcovacsDeebot X5 Pro Plus Firmware< 1.38.0
EcovacsDeebot X5 Pro Plus-
EcovacsDeebot X5 Pro Ultra Firmware< 1.17.0
EcovacsDeebot X5 Pro Ultra-
EcovacsMate X Firmware< 1.44.18
EcovacsMate X-
EcovacsDeebot X1 Omni Firmware< 2.4.41
EcovacsDeebot X1 Omni-
EcovacsDeebot X1 Turbo Firmware< 2.4.41
EcovacsDeebot X1 Turbo-
EcovacsDeebot X1 Pro Omni Firmware< 2.4.41
EcovacsDeebot X1 Pro Omni-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-52330?

CVE-2024-52330 is a vulnerability with a CVSS score of 7.4 (HIGH). ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.

How severe is CVE-2024-52330?

CVE-2024-52330 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-52330?

Check the references section above for vendor advisories and patch information. Affected products include: Ecovacs Deebot X2 Omni Firmware, Ecovacs Deebot X2 Omni, Ecovacs Deebot X2 Combo Firmware, Ecovacs Deebot X2 Combo, Ecovacs Deebot X2S Firmware.