← Volver a CVEs
CVE-2024-52329
HIGH7.4
Descripcion
ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens.
Detalles CVE
Puntuacion CVSS v3.17.4
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vector de ataqueNETWORK
ComplejidadHIGH
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado1/23/2025
Ultima modificacion9/23/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
ecovacs:home
Debilidades (CWE)
CWE-295
Referencias
https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf(9119a7d8-5eab-497f-8521-727c672e3725)
https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdf(9119a7d8-5eab-497f-8521-727c672e3725)
https://www.ecovacs.com/global/userhelp/dsa20241217001(9119a7d8-5eab-497f-8521-727c672e3725)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.