ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 23 Jan 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates. | |
Title | ECOVACS lawnmowers and vacuums do not properly validate TLS certificates | |
Weaknesses | CWE-295 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: cisa-cg
Published: 2025-01-23T16:36:50.128Z
Updated: 2025-02-12T20:41:28.969Z
Reserved: 2024-11-08T01:06:02.405Z
Link: CVE-2024-52330

Updated: 2025-02-12T20:35:32.396Z

Status : Received
Published: 2025-01-23T17:15:14.427
Modified: 2025-01-23T17:15:14.427
Link: CVE-2024-52330

No data.