← Retour aux CVEs
CVE-2020-16169
CRITICAL9.8
Description
Authentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 allows remote attackers to gain elevated privileges on the temi and have it automatically answer the attacker's calls, granting audio, video, and motor control via unspecified vectors.
Details CVE
Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie8/7/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
robotemi:robox_os
Faiblesses (CWE)
CWE-287
References
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/call-an-exorcist-my-robots-possessed/(cve@mitre.org)
https://www.robotemi.com/software-updates/(cve@mitre.org)
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/call-an-exorcist-my-robots-possessed/(af854a3a-2127-422b-91ae-364da2661108)
https://www.robotemi.com/software-updates/(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.