2.4
CVSSv3

CVE-2018-17177

Published: 18/09/2018 Updated: 17/06/2021
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 2.4 | Impact Score: 1.4 | Exploitability Score: 0.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character password of *^JEd4W!I that is obfuscated by hiding it within a custom /bin/rc4_crypt binary.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

neatorobotics botvac d4 connected firmware 2.2.0

neatorobotics botvac d6 connected firmware 2.2.0

neatorobotics botvac d5 connected firmware 2.2.0

neatorobotics botvac d7 connected firmware 2.2.0

neatorobotics botvac d3 connected firmware 2.2.0

neatorobotics botvac 85 firmware 1.2.1