ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 23 Jan 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens. | |
Title | ECOVACS HOME mobile app plugins do not properly validate TLS certificates | |
Weaknesses | CWE-295 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: cisa-cg
Published: 2025-01-23T16:36:06.533Z
Updated: 2025-02-12T20:41:29.110Z
Reserved: 2024-11-08T01:06:02.405Z
Link: CVE-2024-52329

Updated: 2025-02-12T20:35:35.651Z

Status : Received
Published: 2025-01-23T17:15:14.287
Modified: 2025-01-23T17:15:14.287
Link: CVE-2024-52329

No data.