7.5
CVSSv3

CVE-2018-17176

Published: 18/09/2018 Updated: 24/08/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A replay issue exists on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not checked at all.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

neatorobotics botvac d4 connected firmware 2.2.0

neatorobotics botvac d6 connected firmware 2.2.0

neatorobotics botvac d7 connected firmware 2.2.0